CVE-2017-16885
Summary
| CVE | CVE-2017-16885 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-12 17:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Changing Passwords, etc.) allows remote attackers to look for the information without authenticating. The information includes Version of device, Firmware ID, Connected users to device along their MAC Addresses, etc. |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Fiberhome | Lm53q1 | - | All | All | All |
| Hardware | Fiberhome | Lm53q1 | - | All | All | All |
| Operating System | Fiberhome | Lm53q1 Firmware | vh519r05c01s38 | All | All | All |
| Operating System | Fiberhome | Lm53q1 Firmware | vh519r05c01s38 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| FiberHome LM53Q1 - Multiple Vulnerabilities - Hardware webapps Exploit | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| Full Disclosure: FiberHome MIFI LM53Q1 Multiple Vulnerabilities | FULLDISC | seclists.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.