PT-2021-17419 · Realtek · Realtek Xpon Rtl9601D Sdk
Published
2021-03-25
·
Updated
2021-03-30
·
CVE-2021-27372
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Realtek xPON RTL9601D SDK version 1.9
Description
The issue allows attackers to possibly gain access to the device with root permissions via the built-in network monitoring tool and execute arbitrary commands, as passwords are stored in plaintext.
Recommendations
For Realtek xPON RTL9601D SDK version 1.9, consider restricting access to the built-in network monitoring tool to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Realtek Xpon Rtl9601D Sdk