ID

VAR-201811-1124


TITLE

Multiple vulnerabilities in the Cradlepoint Router

Trust: 0.6

sources: CNVD: CNVD-2018-22968

DESCRIPTION

Cradlepoint is the industry leader in 4G/LTE network modems and routers, providing the highest level of solution for enterprise 4G/LTD/Wi-Fi wireless networks and providing management services to ensure optimal network uptime . There are multiple vulnerabilities in CradlepointRouter. The attacker uses hard-coded backdoor credentials to reveal sensitive information such as the WLAN MAC of the target device, while the default password of the Cradlepoint router is four bytes after the WLAN MAC. If the user does not modify the default password, the attacker can use the default password to log in to the device's web management interface and perform a series of malicious operations, including executing commands in the sandbox, enabling SSH services, and so on.

Trust: 0.6

sources: CNVD: CNVD-2018-22968

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-22968

AFFECTED PRODUCTS

vendor:cradlepointmodel:routerscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2018-22968

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2018-22968
value: HIGH

Trust: 0.6

CNVD: CNVD-2018-22968
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2018-22968

EXTERNAL IDS

db:CNVDid:CNVD-2018-22968

Trust: 0.6

sources: CNVD: CNVD-2018-22968

REFERENCES

url:https://seclists.org/fulldisclosure/2018/nov/22

Trust: 0.6

sources: CNVD: CNVD-2018-22968

SOURCES

db:CNVDid:CNVD-2018-22968

LAST UPDATE DATE

2022-05-04T10:26:21.457000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-22968date:2018-11-12T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-22968date:2018-11-12T00:00:00