CVE-2017-16885
Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Changing Passwords, etc.) allows remote attackers to look for the information without authenticating.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 33.5%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Changing Passwords, etc.) allows remote attackers to look for the information without authenticating. The information includes Version of device, Firmware ID, Connected users to device along their MAC Addresses, etc.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 33.45% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- fiberhome/lm53q1 firmware
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2018/Jan/28Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/43460/Exploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Jan/28Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/43460/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.