CVE-2017-9136

An issue was discovered on Mimosa Client Radios before 2.2.3. In the device's web interface, there is a page that allows an attacker to use an unsanitized GET parameter to download files from the device as the root user. The attacker can download any file from the device's filesystem. This can be used to view unsalted, MD5-hashed administrator passwords, which can then be cracked, giving the attacker full admin access to the device's web interface. This vulnerability can also be used to view the plaintext pre-shared key (PSK) for encrypted wireless connections, or to view the device's serial number (which allows an attacker to factory reset the device).
References
Link Resource
http://blog.iancaling.com/post/160596244178 Third Party Advisory
http://blog.iancaling.com/post/160596244178 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:mimosa:backhaul_radios:*:*:*:*:*:*:*:*
cpe:2.3:o:mimosa:client_radios:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:35

Type Values Removed Values Added
References () http://blog.iancaling.com/post/160596244178 - Third Party Advisory () http://blog.iancaling.com/post/160596244178 - Third Party Advisory

Information

Published : 2017-05-21 21:29

Updated : 2024-11-21 03:35


NVD link : CVE-2017-9136

Mitre link : CVE-2017-9136

CVE.ORG link : CVE-2017-9136


JSON object : View

Products Affected

mimosa

  • client_radios
  • backhaul_radios
CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm

CWE-522

Insufficiently Protected Credentials

CWE-732

Incorrect Permission Assignment for Critical Resource