ID

VAR-201807-2275


TITLE

Dr.COM APG anti-proxy gateway has SQL injection vulnerability

Trust: 0.6

sources: CNVD: CNVD-2018-10537

DESCRIPTION

Dr.COM APG Anti-Proxy Gateway is a network behavior analysis and management gateway device specially designed and developed for broadband shared access management in Guangzhou Hotspot. It mainly provides wired and wireless broadband operators with shared user access Control boxes and monitor in real time to avoid potential risks and losses caused by shared access behaviors, and make operators' network operations more healthy, orderly and sustainable development. There is a SQL injection vulnerability in Dr.COM APG anti-proxy gateway. An attacker can use this vulnerability to obtain sensitive database information.

Trust: 0.6

sources: CNVD: CNVD-2018-10537

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-10537

AFFECTED PRODUCTS

vendor:hotspotmodel:dr.com anti-proxy gateway management systemscope:lteversion:<=1.1

Trust: 0.6

sources: CNVD: CNVD-2018-10537

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2018-10537
value: HIGH

Trust: 0.6

CNVD: CNVD-2018-10537
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2018-10537

PATCH

title:Dr.COM APG anti-proxy gateway has SQL injection vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/130327

Trust: 0.6

sources: CNVD: CNVD-2018-10537

EXTERNAL IDS

db:CNVDid:CNVD-2018-10537

Trust: 0.6

sources: CNVD: CNVD-2018-10537

SOURCES

db:CNVDid:CNVD-2018-10537

LAST UPDATE DATE

2022-05-04T09:10:42.903000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-10537date:2018-05-31T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-10537date:2018-07-10T00:00:00