PT-2019-9123 · Telus · Telus Actiontec Web6000Q
Andrew Klaus
·
Published
2019-06-11
·
Updated
2020-08-24
·
CVE-2018-15555
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Telus Actiontec WEB6000Q version 1.1.02.22
Description
The issue allows an attacker to gain root level access on the device using the username "root" and password "admin" through the enabled onboard UART headers. This provides an attacker with elevated privileges, potentially leading to further exploitation.
Recommendations
For Telus Actiontec WEB6000Q version 1.1.02.22, consider disabling the onboard UART headers to prevent unauthorized access until a patch is available. Additionally, changing the default password for the "root" user can help mitigate the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telus Actiontec Web6000Q