PT-2020-12955 · Iqrouter · Iqrouter

Ilya Shaposhnikov

·

Published

2020-04-21

·

Updated

2024-08-04

·

CVE-2020-11964

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions IQrouter versions 3.3.1 and earlier
Description The issue allows remote attackers to change the root password arbitrarily using the Lua function diag set password in the web-panel. This can occur on a brand-new network that has not been configured with a secure password.
Recommendations For IQrouter versions 3.3.1 and earlier, consider disabling the diag set password function in the web-panel until a secure configuration can be applied, and ensure a secure password is set during the initial configuration to prevent exploitation.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2020-11964

Affected Products

Iqrouter