{"api_version":"1","generated_at":"2026-07-23T12:48:40+00:00","cve":"CVE-2019-13140","urls":{"html":"https://cve.report/CVE-2019-13140","api":"https://cve.report/api/cve/CVE-2019-13140.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-13140","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-13140"},"summary":{"title":"CVE-2019-13140","description":"Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the \"user\" account to extract the 3DES key via JSON commands to ubus. The 3DES key is used to decrypt the provisioning file provided by Adamo Telecom on a public URL via cleartext HTTP.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-09-16 17:15:00","updated_at":"2022-03-31 17:47:00"},"problem_types":["CWE-552"],"metrics":[],"references":[{"url":"https://www.exploit-db.com/docs/47397","name":"https://www.exploit-db.com/docs/47397","refsource":"MISC","tags":[],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/47390","name":"47390","refsource":"EXPLOIT-DB","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Inteno IOPSYS Gateway - Improper Access Restrictions - Hardware remote Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://twitter.com/GerardFuguet/status/1169298861782896642","name":"https://twitter.com/GerardFuguet/status/1169298861782896642","refsource":"MISC","tags":["Third Party Advisory"],"title":"Gerard Fuguet Morales on Twitter: \"The Common Vulnerabilities and Exposures (CVE) Program has assigned the CVE ID: CVE-2019-13140 to this vulnerability.\nhttps://t.co/pkBHhzRhE3… https://t.co/S7Ev7pvPv2\"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/154494/Inteno-IOPSYS-Gateway-3DES-Key-Extraction-Improper-Access.html","name":"http://packetstormsecurity.com/files/154494/Inteno-IOPSYS-Gateway-3DES-Key-Extraction-Improper-Access.html","refsource":"MISC","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Inteno IOPSYS Gateway 3DES Key Extraction Improper Access ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-13140","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-13140","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"13140","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"intenogroup","cpe5":"eg200","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"13140","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"intenogroup","cpe5":"eg200","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"13140","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"intenogroup","cpe5":"eg200_firmware","cpe6":"eg200-wu7p1u_adamo3.16.4-190226_1650","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"13140","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"intenogroup","cpe5":"eg200_firmware","cpe6":"eg200-wu7p1u_adamo3.16.4-190226_1650","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-13140","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the \"user\" account to extract the 3DES key via JSON commands to ubus. The 3DES key is used to decrypt the provisioning file provided by Adamo Telecom on a public URL via cleartext HTTP."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"EXPLOIT-DB","name":"47390","url":"https://www.exploit-db.com/exploits/47390"},{"refsource":"MISC","name":"https://twitter.com/GerardFuguet/status/1169298861782896642","url":"https://twitter.com/GerardFuguet/status/1169298861782896642"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/154494/Inteno-IOPSYS-Gateway-3DES-Key-Extraction-Improper-Access.html","url":"http://packetstormsecurity.com/files/154494/Inteno-IOPSYS-Gateway-3DES-Key-Extraction-Improper-Access.html"},{"refsource":"MISC","name":"https://www.exploit-db.com/docs/47397","url":"https://www.exploit-db.com/docs/47397"}]}},"nvd":{"publishedDate":"2019-09-16 17:15:00","lastModifiedDate":"2022-03-31 17:47:00","problem_types":["CWE-552"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:intenogroup:eg200_firmware:eg200-wu7p1u_adamo3.16.4-190226_1650:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:intenogroup:eg200:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"13140","Ordinal":"151498","Title":"CVE-2019-13140","CVE":"CVE-2019-13140","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"13140","Ordinal":"1","NoteData":"Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the \"user\" account to extract the 3DES key via JSON commands to ubus. The 3DES key is used to decrypt the provisioning file provided by Adamo Telecom on a public URL via cleartext HTTP.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"13140","Ordinal":"2","NoteData":"2019-09-16","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"13140","Ordinal":"3","NoteData":"2019-09-18","Type":"Other","Title":"Modified"}]}}}