PT-2019-7955 · Starry · Starry Station

Published

2019-06-10

·

Updated

2019-06-11

·

CVE-2017-13718

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Starry Station (aka Starry Router) (affected versions not specified)
Description The HTTP API supported by the device allows brute forcing the PIN setup by the user, enabling an attacker to change Wi-Fi settings and PIN, as well as port forward and expose internal devices' ports to the Internet. The device uses custom Python code called "rodman" that allows the mobile application to interact with the device using a secret, which is a uuid4 based session identifier, or a security code, which is the PIN number set by the user. An attacker on the Internet can interact with the router's HTTP interface when a user navigates to the attacker's website and brute force the credentials. The device's server sets the Access-Control-Allow-Origin header to "*", allowing an attacker to easily interact with the JSON payload returned by the device and steal sensitive information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-13718

Affected Products

Starry Station