CVE-2019-20004

An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete control of the router.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:intelbras:iwr_3000n_firmware:1.8.7:*:*:*:*:*:*:*
cpe:2.3:h:intelbras:iwr_3000n:-:*:*:*:*:*:*:*

History

07 Nov 2023, 03:08

Type Values Removed Values Added
References
  • {'url': 'https://medium.com/@rsantos_14778/remote-control-cve-2019-20004-21f77e976715', 'name': 'https://medium.com/@rsantos_14778/remote-control-cve-2019-20004-21f77e976715', 'tags': ['Exploit', 'Third Party Advisory'], 'refsource': 'MISC'}
  • () https://medium.com/%40rsantos_14778/remote-control-cve-2019-20004-21f77e976715 -

Information

Published : 2020-01-05 23:15

Updated : 2024-02-28 17:28


NVD link : CVE-2019-20004

Mitre link : CVE-2019-20004

CVE.ORG link : CVE-2019-20004


JSON object : View

Products Affected

intelbras

  • iwr_3000n_firmware
  • iwr_3000n
CWE
CWE-640

Weak Password Recovery Mechanism for Forgotten Password