PT-2020-16337 · Askey+1 · Askey Ap5100W Dual Sig+1
Published
2020-12-10
·
Updated
2022-08-06
·
CVE-2020-26201
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Askey AP5100W Dual SIG versions 1.01.097 and all prior versions
Description
The issue allows an attacker to gain unauthorized access as an admin or root user to the device Operating System via Telnet or SSH, due to a weak password used at the Operating System (rlx-linux) level.
Recommendations
For Askey AP5100W Dual SIG versions 1.01.097 and all prior versions, consider changing the default password to a strong one to prevent unauthorized access.
As a temporary workaround, consider disabling Telnet and SSH access to the device until a patch is available.
Restrict access to the device Operating System to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Askey Ap5100W Dual Sig
Rlx-Linux