CVE-2018-6312
Summary
| CVE | CVE-2018-6312 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-10 22:29:00 UTC |
| Updated | 2021-09-09 13:35:00 UTC |
| Description | A privileged account with a weak default password on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 can be used to turn on the TELNET service via the web interface, which allows root login without any password. This vulnerability will lead to full system compromise and disclosure of user communications. The foxconn account with an 8-character lowercase alphabetic password can be used. |
Risk And Classification
Problem Types: CWE-521
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Foxconn | Ap-fc4064-t | - | All | All | All |
| Operating System | Foxconn | Ap-fc4064-t Firmware | ap_gt_b38_5.8.3lb15-w47_lte | All | All | All |
| Hardware | Foxconn | Femtocell Femto Ap-fc4064-t | - | All | All | All |
| Hardware | Foxconn | Femtocell Femto Ap-fc4064-t | - | All | All | All |
| Operating System | Foxconn | Femtocell Femto Ap-fc4064-t Firmware | ap_gt_b38_5.8.3lb15-w47_lte | All | All | All |
| Operating System | Foxconn | Femtocell Femto Ap-fc4064-t Firmware | ap_gt_b38_5.8.3lb15-w47_lte | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [CVE-2018-6311 and CVE-2018-6312] Foxconn femtocell remote and local root access Raw · GitHub | MISC | gist.github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.