CVE-2017-6896

Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to admin privilege just by modifying the Base64-encoded session cookie value.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:digisol:dg-hr1400_router_firmware:1.00.02:*:*:*:*:*:*:*
cpe:2.3:h:digisol:dg-hr1400_router:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:30

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2017/Mar/52 - () http://seclists.org/fulldisclosure/2017/Mar/52 -
References () https://drive.google.com/file/d/0B6715xUqH18MX29uRlpaSVJ4OTA/view?usp=sharing - Third Party Advisory () https://drive.google.com/file/d/0B6715xUqH18MX29uRlpaSVJ4OTA/view?usp=sharing - Third Party Advisory
References () https://packetstormsecurity.com/files/141693/digisol-escalate.txt - () https://packetstormsecurity.com/files/141693/digisol-escalate.txt -
References () https://www.exploit-db.com/exploits/41633/ - () https://www.exploit-db.com/exploits/41633/ -
References () https://www.indrajithan.com/DIGISOL_router_previlage_escaltion - Exploit, Third Party Advisory () https://www.indrajithan.com/DIGISOL_router_previlage_escaltion - Exploit, Third Party Advisory

Information

Published : 2017-03-14 20:59

Updated : 2024-11-21 03:30


NVD link : CVE-2017-6896

Mitre link : CVE-2017-6896

CVE.ORG link : CVE-2017-6896


JSON object : View

Products Affected

digisol

  • dg-hr1400_router_firmware
  • dg-hr1400_router
CWE
CWE-565

Reliance on Cookies without Validation and Integrity Checking