CVE-2020-9477
Summary
| CVE | CVE-2020-9477 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-04 19:15:00 UTC |
| Updated | 2023-11-07 03:26:00 UTC |
| Description | An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices. A vulnerability in the authentication functionality in the web-based interface could allow an unauthenticated remote attacker to capture packets at the time of authentication and gain access to the cleartext password. An attacker could use this access to create a new user account or control the device. |
Risk And Classification
Problem Types: CWE-319
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Humaxdigital | Hga12r-02 | - | All | All | All |
| Hardware | Humaxdigital | Hga12r-02 | - | All | All | All |
| Operating System | Humaxdigital | Hga12r-02 Firmware | brgcaa1.1.53 | All | All | All |
| Operating System | Humaxdigital | Hga12r-02 Firmware | brgcaa1.1.53 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Info disclosure — CVE-2020–9477. A vulnerability in the authentication… | by Rafael Silva | Medium | medium.com | ||
| HGA12R-02 | HUMAX-United Kingdom | MISC | uk.humaxdigital.com | Product, Vendor Advisory |
| Info disclosure — CVE-2020–9477. A vulnerability in the authentication… | by Rafael Silva | Medium | MISC | medium.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.