PT-2020-20287 · Juplink · Juplink Rx4-1500
Published
2020-04-23
·
Updated
2020-05-06
·
CVE-2020-8798
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Juplink RX4-1500 versions 1.0.3 through 1.0.5
Description
The issue allows remote attackers to change or access router settings by connecting to the unauthenticated "setup3.htm" endpoint from the local network.
Recommendations
For versions 1.0.3 through 1.0.5, as a temporary workaround, consider restricting access to the "setup3.htm" endpoint until a patch is available.
Exploit
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Juplink Rx4-1500