VulnerabilityModified
CVE-2015-7282
ReadyNet WRT300N-DD devices with firmware 1.0.26 use the same source port number for every DNS query, which makes it easier for remote attackers to spoof responses by selecting that number for the destination port.
MEDIUM 5.8EPSS 0.98%
Does this matter?
Lower severity and a low EPSS score (0.98%). Track it; it rarely justifies an emergency change on its own.
Description
ReadyNet WRT300N-DD devices with firmware 1.0.26 use the same source port number for every DNS query, which makes it easier for remote attackers to spoof responses by selecting that number for the destination port.
- CVSS 3.0
- 5.8 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
- EPSS
- 0.98% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- readynet solutions/wrt300n-dd firmware · readynet solutions/wrt300n-dd
- Source
- cret@cert.org
References
- http://www.securityfocus.com/bid/78814
- https://www.kb.cert.org/vuls/id/167992Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/78814
- https://www.kb.cert.org/vuls/id/167992Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.