CVE-2018-13109
Summary
| CVE | CVE-2018-13109 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-06 14:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able to access and manipulate settings within the web interface that are forbidden to end users (e.g., by the ISP). An attacker would be able to enable the TELNET server or other settings as well. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Adbglobal | Dv2210 | - | All | All | All |
| Hardware | Adbglobal | Dv2210 | - | All | All | All |
| Operating System | Adbglobal | Dv2210 Firmware | - | All | All | All |
| Operating System | Adbglobal | Dv2210 Firmware | - | All | All | All |
| Hardware | Adbglobal | Prg Av4202n | - | All | All | All |
| Hardware | Adbglobal | Prg Av4202n | - | All | All | All |
| Operating System | Adbglobal | Prg Av4202n Firmware | - | All | All | All |
| Operating System | Adbglobal | Prg Av4202n Firmware | - | All | All | All |
| Hardware | Adbglobal | Vv2220 | - | All | All | All |
| Hardware | Adbglobal | Vv2220 | - | All | All | All |
| Operating System | Adbglobal | Vv2220 Firmware | - | All | All | All |
| Operating System | Adbglobal | Vv2220 Firmware | - | All | All | All |
| Hardware | Adbglobal | Vv5522 | - | All | All | All |
| Hardware | Adbglobal | Vv5522 | - | All | All | All |
| Operating System | Adbglobal | Vv5522 Firmware | - | All | All | All |
| Operating System | Adbglobal | Vv5522 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: SEC Consult SA-20180704-1 :: Authorization Bypass in all ADB Broadband Gateways / Routers | FULLDISC | seclists.org | Mailing List, Third Party Advisory |
| ADB Broadband Gateways / Routers - Authorization Bypass - Hardware webapps Exploit | EXPLOIT-DB | www.exploit-db.com | Third Party Advisory, VDB Entry |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Authorization Bypass in all ADB Broadband Gateways / Routers – SEC Consult | MISC | www.sec-consult.com | Exploit, Third Party Advisory |
| ADB Authorization Bypass ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.