ID

VAR-201810-0085


CVE

CVE-2018-10532


TITLE

EE 4GEE Vulnerabilities related to the use of hard-coded credentials on devices

Trust: 0.8

sources: JVNDB: JVNDB-2018-014070

DESCRIPTION

An issue was discovered on EE 4GEE HH70VB-2BE8GB3 HH70_E1_02.00_19 devices. Hardcoded root SSH credentials were discovered to be stored within the "core_app" binary utilised by the EE router for networking services. An attacker with knowledge of the default password (oelinux123) could login to the router via SSH as the root user, which could allow for the loss of confidentiality, integrity, and availability of the system. This would also allow for the bypass of the "AP Isolation" mode that is supported by the router, as well as the settings for multiple Wireless networks, which a user may use for guest clients. EE 4GEE The device contains a vulnerability related to the use of hard-coded credentials.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. The EE4GEEHH70HomeRouter is a home router. The EE4GEEHH70HomeRouter has a hard-coded RootSSH credential vulnerability. EE 4GEE HH70VB-2BE8GB3 is a home gateway product

Trust: 2.25

sources: NVD: CVE-2018-10532 // JVNDB: JVNDB-2018-014070 // CNVD: CNVD-2018-22245 // VULHUB: VHN-120301

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-22245

AFFECTED PRODUCTS

vendor:eemodel:4geescope:eqversion:hh70_e1_02.00_19

Trust: 1.0

vendor:eemodel:4gee wifiscope:eqversion:hh70vb-2be8gb3 hh70_e1_02.00_19

Trust: 0.8

vendor:eemodel:limited 4gee router hh70vb-2be8gb3 hh70 e1 02.00 19scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2018-22245 // JVNDB: JVNDB-2018-014070 // NVD: CVE-2018-10532

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-10532
value: HIGH

Trust: 1.0

NVD: CVE-2018-10532
value: HIGH

Trust: 0.8

CNVD: CNVD-2018-22245
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201810-1438
value: HIGH

Trust: 0.6

VULHUB: VHN-120301
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-10532
severity: HIGH
baseScore: 8.3
vectorString: AV:A/AC:L/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-22245
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-120301
severity: HIGH
baseScore: 8.3
vectorString: AV:A/AC:L/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-10532
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-22245 // VULHUB: VHN-120301 // JVNDB: JVNDB-2018-014070 // CNNVD: CNNVD-201810-1438 // NVD: CVE-2018-10532

PROBLEMTYPE DATA

problemtype:CWE-798

Trust: 1.9

sources: VULHUB: VHN-120301 // JVNDB: JVNDB-2018-014070 // NVD: CVE-2018-10532

THREAT TYPE

specific network environment

Trust: 0.6

sources: CNNVD: CNNVD-201810-1438

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201810-1438

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-014070

PATCH

title:4GEE WiFiurl:https://ee.co.uk/help/help-new/home-broadband-ee-tv-home-phone-and-4gee-wifi/4gee-wifi/getting-started-on-4gee-wifi

Trust: 0.8

title:EE4GEEHH70HomeRouter Hardcoded Patch for RootSSH Credential Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/143525

Trust: 0.6

sources: CNVD: CNVD-2018-22245 // JVNDB: JVNDB-2018-014070

EXTERNAL IDS

db:NVDid:CVE-2018-10532

Trust: 3.1

db:JVNDBid:JVNDB-2018-014070

Trust: 0.8

db:CNNVDid:CNNVD-201810-1438

Trust: 0.7

db:CNVDid:CNVD-2018-22245

Trust: 0.6

db:PACKETSTORMid:150100

Trust: 0.1

db:VULHUBid:VHN-120301

Trust: 0.1

sources: CNVD: CNVD-2018-22245 // VULHUB: VHN-120301 // JVNDB: JVNDB-2018-014070 // CNNVD: CNNVD-201810-1438 // NVD: CVE-2018-10532

REFERENCES

url:https://blog.jameshemmings.co.uk/2018/10/24/4gee-hh70-router-vulnerability-disclosure/

Trust: 2.5

url:https://www.theregister.co.uk/2018/10/26/ee_4gee_hh70_ssh_backdoor/

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-10532

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-10532

Trust: 0.8

url:https://seclists.org/fulldisclosure/2018/oct/52

Trust: 0.6

sources: CNVD: CNVD-2018-22245 // VULHUB: VHN-120301 // JVNDB: JVNDB-2018-014070 // CNNVD: CNNVD-201810-1438 // NVD: CVE-2018-10532

SOURCES

db:CNVDid:CNVD-2018-22245
db:VULHUBid:VHN-120301
db:JVNDBid:JVNDB-2018-014070
db:CNNVDid:CNNVD-201810-1438
db:NVDid:CVE-2018-10532

LAST UPDATE DATE

2024-11-23T22:51:59.434000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-22245date:2018-11-02T00:00:00
db:VULHUBid:VHN-120301date:2019-01-30T00:00:00
db:JVNDBid:JVNDB-2018-014070date:2019-03-11T00:00:00
db:CNNVDid:CNNVD-201810-1438date:2019-04-01T00:00:00
db:NVDid:CVE-2018-10532date:2024-11-21T03:41:30.490

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-22245date:2018-10-31T00:00:00
db:VULHUBid:VHN-120301date:2018-10-30T00:00:00
db:JVNDBid:JVNDB-2018-014070date:2019-03-11T00:00:00
db:CNNVDid:CNNVD-201810-1438date:2018-10-31T00:00:00
db:NVDid:CVE-2018-10532date:2018-10-30T18:29:00.330