PT-2019-18521 · Linksys · Linksys Wrt1900Acs

T0B0Rx0R

·

Published

2019-06-06

·

Updated

2021-07-21

·

CVE-2019-7311

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linksys WRT1900ACS version 1.0.3.187766
Description The issue concerns a lack of encryption in storing the user login cookie, specifically the admin-auth cookie, which contains the admin password in base64 cleartext. This allows a local attacker to discover the admin password and gain administrative access to the router. An attacker can exploit this by sniffing the network during login or by gaining physical access to the victim's computer soon after an administrative login.
Recommendations For Linksys WRT1900ACS version 1.0.3.187766, consider changing the admin password regularly and avoiding using the same password across multiple devices as a temporary mitigation measure. Restrict access to the router's administrative interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-7311

Affected Products

Linksys Wrt1900Acs