ID

VAR-201906-1177


CVE

CVE-2018-20841


TITLE

HooToo TripMate Titan HT-TM05 and HT-05 In router firmware OS Command injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2018-015609

DESCRIPTION

HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in the mac parameter of a protocol.csp?function=set&fname=security&opt=mac_table request. HooToo TripMate Titan HT-TM05 and HT-05 Router firmware includes OS A command injection vulnerability exists.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. HooToo TripMate Titan HT-TM05 is a portable wireless router produced by American company HooToo. The vulnerability stems from the fact that the network system or product does not correctly filter special characters, commands, etc. in the process of constructing executable commands of the operating system from external input data. Attackers can exploit this vulnerability to execute illegal operating system commands

Trust: 1.8

sources: NVD: CVE-2018-20841 // JVNDB: JVNDB-2018-015609 // VULHUB: VHN-131688 // VULMON: CVE-2018-20841

AFFECTED PRODUCTS

vendor:hootoomodel:tripmate titan ht-tm05scope:eqversion:2.000.022

Trust: 1.8

vendor:hootoomodel:tripmate titan ht-tm05scope:eqversion:2.000.082

Trust: 1.8

sources: JVNDB: JVNDB-2018-015609 // NVD: CVE-2018-20841

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-20841
value: CRITICAL

Trust: 1.0

NVD: CVE-2018-20841
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-201906-398
value: CRITICAL

Trust: 0.6

VULHUB: VHN-131688
value: HIGH

Trust: 0.1

VULMON: CVE-2018-20841
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-20841
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-131688
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-20841
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-131688 // VULMON: CVE-2018-20841 // JVNDB: JVNDB-2018-015609 // CNNVD: CNNVD-201906-398 // NVD: CVE-2018-20841

PROBLEMTYPE DATA

problemtype:CWE-78

Trust: 1.9

sources: VULHUB: VHN-131688 // JVNDB: JVNDB-2018-015609 // NVD: CVE-2018-20841

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201906-398

TYPE

operating system commend injection

Trust: 0.6

sources: CNNVD: CNNVD-201906-398

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-015609

PATCH

title:HT-TM05 TripMate Versatile Wireless N Travel Routerurl:https://www.hootoo.com/hootoo-tripmate-ht-tm05-wireless-router.html

Trust: 0.8

sources: JVNDB: JVNDB-2018-015609

EXTERNAL IDS

db:NVDid:CVE-2018-20841

Trust: 2.6

db:EXPLOIT-DBid:46143

Trust: 1.8

db:JVNDBid:JVNDB-2018-015609

Trust: 0.8

db:CNNVDid:CNNVD-201906-398

Trust: 0.7

db:VULHUBid:VHN-131688

Trust: 0.1

db:VULMONid:CVE-2018-20841

Trust: 0.1

sources: VULHUB: VHN-131688 // VULMON: CVE-2018-20841 // JVNDB: JVNDB-2018-015609 // CNNVD: CNNVD-201906-398 // NVD: CVE-2018-20841

REFERENCES

url:https://ioactive.com/hootoo-tripmate-routers-are-cute-but/

Trust: 2.6

url:https://www.exploit-db.com/exploits/46143

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-20841

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-20841

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/78.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-131688 // VULMON: CVE-2018-20841 // JVNDB: JVNDB-2018-015609 // CNNVD: CNNVD-201906-398 // NVD: CVE-2018-20841

SOURCES

db:VULHUBid:VHN-131688
db:VULMONid:CVE-2018-20841
db:JVNDBid:JVNDB-2018-015609
db:CNNVDid:CNNVD-201906-398
db:NVDid:CVE-2018-20841

LAST UPDATE DATE

2024-11-23T22:41:28.759000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-131688date:2019-06-12T00:00:00
db:VULMONid:CVE-2018-20841date:2019-06-12T00:00:00
db:JVNDBid:JVNDB-2018-015609date:2019-06-20T00:00:00
db:CNNVDid:CNNVD-201906-398date:2019-06-13T00:00:00
db:NVDid:CVE-2018-20841date:2024-11-21T04:02:17.343

SOURCES RELEASE DATE

db:VULHUBid:VHN-131688date:2019-06-11T00:00:00
db:VULMONid:CVE-2018-20841date:2019-06-11T00:00:00
db:JVNDBid:JVNDB-2018-015609date:2019-06-20T00:00:00
db:CNNVDid:CNNVD-201906-398date:2019-06-11T00:00:00
db:NVDid:CVE-2018-20841date:2019-06-11T21:29:00.567