PT-2024-29868 · Digisol · Digisol Router
Ganesh Bakare
+2
·
Published
2024-05-10
·
Updated
2024-07-03
·
CVE-2024-4232
CVSS v3.1
4.1
Medium
| Vector | AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Digisol Router (DG-GR1321) version v3.2.02
Description
This issue is caused by the lack of encryption or hashing in storing passwords within the router's firmware/database. An attacker with physical access could exploit this by extracting the firmware and reverse-engineering the binary data to access plaintext passwords. Successful exploitation could allow the attacker to gain unauthorized access to the targeted system.
Recommendations
For Digisol Router (DG-GR1321) version v3.2.02, consider changing passwords and restricting physical access to the device until a patch is available. As a temporary workaround, restrict access to the router's firmware and database to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Digisol Router