ID

VAR-201310-0800


TITLE

Multiple holes exist in FiberHome Modem Router HG-110

Trust: 0.6

sources: CNVD: CNVD-2013-13993

DESCRIPTION

FiberHome Modem Router HG-110 is a wireless home gateway product. FiberHome Modem Router HG-110 firmware HG110_BH_V1.6 version has directory traversal and security measures to bypass the vulnerability. Successful exploitation allows remote attackers to bypass authentication and remotely change DNS. Exploiting these issues will allow an attacker to bypass security restrictions, perform unauthorized actions and access, read and execute files outside the webroot folder. Information harvested may aid in launching further attacks

Trust: 0.81

sources: CNVD: CNVD-2013-13993 // BID: 63235

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-13993

AFFECTED PRODUCTS

vendor:fiberhomemodel:hg-110 hg110 bh v1.6scope: - version: -

Trust: 0.6

vendor:fiberhomemodel:hg-110scope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2013-13993 // BID: 63235

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2013-13993
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2013-13993
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2013-13993

THREAT TYPE

network

Trust: 0.3

sources: BID: 63235

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 63235

EXTERNAL IDS

db:BIDid:63235

Trust: 0.9

db:CNVDid:CNVD-2013-13993

Trust: 0.6

sources: CNVD: CNVD-2013-13993 // BID: 63235

REFERENCES

url:http://www.securityfocus.com/bid/63235

Trust: 0.6

url:http://hk.fiberhomegroup.com/

Trust: 0.3

sources: CNVD: CNVD-2013-13993 // BID: 63235

CREDITS

Javier Perez

Trust: 0.3

sources: BID: 63235

SOURCES

db:CNVDid:CNVD-2013-13993
db:BIDid:63235

LAST UPDATE DATE

2022-05-17T01:48:04.030000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-13993date:2013-10-24T00:00:00
db:BIDid:63235date:2013-09-22T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-13993date:2013-10-24T00:00:00
db:BIDid:63235date:2013-09-22T00:00:00