PT-2019-14990 · Fiberhome · Fiberhome Hg2201T

Published

2019-10-08

·

Updated

2021-07-21

·

CVE-2019-17186

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FiberHome HG2201T version 1.00.M5007 JS 201804
Description The issue allows for pre-authentication remote code execution on the /var/WEB-GUI/cgi-bin/telnet.cgi endpoint.
Recommendations For FiberHome HG2201T version 1.00.M5007 JS 201804, as a temporary workaround, consider disabling access to the /var/WEB-GUI/cgi-bin/telnet.cgi endpoint until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-17186

Affected Products

Fiberhome Hg2201T