PT-2021-11576 · Askey · Askey Fiber Router Rtf3505Vw-N1
Published
2021-03-26
·
Updated
2022-07-12
·
CVE-2020-28695
CVSS v2.0
8.3
High
| Vector | AV:A/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Askey Fiber Router RTF3505VW-N1 version BR SV g000 R3505VWN1001 s32 7
Description:
The issue allows for Remote Code Execution and retrieval of admin credentials, enabling access to the Dashboard or login via SSH, which can lead to code execution as root.
Recommendations:
For Askey Fiber Router RTF3505VW-N1 version BR SV g000 R3505VWN1001 s32 7, consider restricting access to the SSH login and Dashboard until a fix is available. As a temporary workaround, restrict the use of admin credentials to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Askey Fiber Router Rtf3505Vw-N1