PT-2021-11576 · Askey · Askey Fiber Router Rtf3505Vw-N1

Published

2021-03-26

·

Updated

2022-07-12

·

CVE-2020-28695

CVSS v2.0

8.3

High

VectorAV:A/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Askey Fiber Router RTF3505VW-N1 version BR SV g000 R3505VWN1001 s32 7
Description: The issue allows for Remote Code Execution and retrieval of admin credentials, enabling access to the Dashboard or login via SSH, which can lead to code execution as root.
Recommendations: For Askey Fiber Router RTF3505VW-N1 version BR SV g000 R3505VWN1001 s32 7, consider restricting access to the SSH login and Dashboard until a fix is available. As a temporary workaround, restrict the use of admin credentials to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-28695

Affected Products

Askey Fiber Router Rtf3505Vw-N1