CVE-2005-1566
Acrowave AAP-3100AR wireless router allows remote attackers to bypass authentication by pressing CTRL-C at the username or password prompt in a telnet session, which causes the shell to crash and restart, then leave the user in the new shell.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.64%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Acrowave AAP-3100AR wireless router allows remote attackers to bypass authentication by pressing CTRL-C at the username or password prompt in a telnet session, which causes the shell to crash and restart, then leave the user in the new shell.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.64% probability · 75th percentile
- CISA KEV
- Not listed
- Affected
- arcowave systems/wlan ap \+ adsl router
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=111592452331677&w=2
- http://secunia.com/advisories/15343Vendor Advisory
- http://www.osvdb.org/16445Vendor Advisory
- http://marc.info/?l=bugtraq&m=111592452331677&w=2
- http://secunia.com/advisories/15343Vendor Advisory
- http://www.osvdb.org/16445Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.