ID

VAR-202108-2316


TITLE

Xiaodu routing has unauthorized access vulnerabilities

Trust: 0.6

sources: CNVD: CNVD-2021-50151

DESCRIPTION

Xiaodu Router is a smart router product launched by Baidu, which can transmit cloud data at will and supports remote download of audio and video resources. Xiaodu routing has unauthorized access vulnerabilities, and attackers can use vulnerabilities to obtain sensitive information.

Trust: 0.6

sources: CNVD: CNVD-2021-50151

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-50151

AFFECTED PRODUCTS

vendor:baidu netcommodel:xiaodu routingscope:eqversion:v1.0.1.10

Trust: 0.6

sources: CNVD: CNVD-2021-50151

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2021-50151
value: LOW

Trust: 0.6

CNVD: CNVD-2021-50151
severity: LOW
baseScore: 3.3
vectorString: AV:A/AC:L/AU:N/C:P/I:N/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 6.5
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2021-50151

EXTERNAL IDS

db:CNVDid:CNVD-2021-50151

Trust: 0.6

sources: CNVD: CNVD-2021-50151

SOURCES

db:CNVDid:CNVD-2021-50151

LAST UPDATE DATE

2022-05-04T09:49:48.006000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-50151date:2021-07-13T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-50151date:2021-08-09T00:00:00