CVE-2019-13140
Summary
| CVE | CVE-2019-13140 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-16 17:15:00 UTC |
| Updated | 2022-03-31 17:47:00 UTC |
| Description | Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the "user" account to extract the 3DES key via JSON commands to ubus. The 3DES key is used to decrypt the provisioning file provided by Adamo Telecom on a public URL via cleartext HTTP. |
Risk And Classification
Problem Types: CWE-552
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Intenogroup | Eg200 | - | All | All | All |
| Hardware | Intenogroup | Eg200 | - | All | All | All |
| Operating System | Intenogroup | Eg200 Firmware | eg200-wu7p1u_adamo3.16.4-190226_1650 | All | All | All |
| Operating System | Intenogroup | Eg200 Firmware | eg200-wu7p1u_adamo3.16.4-190226_1650 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.exploit-db.com/docs/47397 | MISC | www.exploit-db.com | |
| Inteno IOPSYS Gateway - Improper Access Restrictions - Hardware remote Exploit | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| Gerard Fuguet Morales on Twitter: "The Common Vulnerabilities and Exposures (CVE) Program has assigned the CVE ID: CVE-2019-13140 to this vulnerability. https://t.co/pkBHhzRhE3… https://t.co/S7Ev7pvPv2" | MISC | twitter.com | Third Party Advisory |
| Inteno IOPSYS Gateway 3DES Key Extraction Improper Access ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.