PT-2019-16602 · Wifi Soft · Wifi-Soft Unibox Controller
Sahil Dhar
·
Published
2019-03-18
·
Updated
2021-09-13
·
CVE-2019-3497
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Wifi-soft UniBox controller versions 0.x through 2.x
Description
An issue in the Diagnostic Tools component of the Wifi-soft UniBox controller allows for Remote Command Execution. This is due to the
tools/ping Ping feature being vulnerable, enabling an attacker to execute arbitrary system commands on the server with root user privileges. The authentication for accessing this component can be bypassed by utilizing hard-coded credentials.Recommendations
For Wifi-soft UniBox controller versions 0.x through 2.x, consider disabling the
tools/ping Ping feature in the Diagnostic Tools component until a patch is available to prevent Remote Command Execution. Restrict access to the Diagnostic Tools component to minimize the risk of exploitation. Avoid using hard-coded credentials for authentication.Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wifi-Soft Unibox Controller