V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2017-6558
CVE
CriticalConfirmedExploit available

iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allo…

CVSS
9.8
Critical
EPSS
0.35
p97
Published
2017-01-01
Updated
2017-01-01
Description

iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the password.cgi file.

Tags · CWE
Pre-auth
CWE-798
CAPEC-70
CAPEC-191
Affected products
Ib-wra150n_firmware
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2017-01-01
Published
2017-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.348 · p97
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-70 · CWE-798
└ via CAPEC-191 · CWE-798
Known exploits — Сканер-ВС
42591
exploitdb · https://www.exploit-db.com/exploits/42591
Enterprise
Affected software
ProductVendorStatus
ib-wra150n_firmware*Tracked
Source databases
CVE