An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete control of the router.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 04:37
Type | Values Removed | Values Added |
---|---|---|
References | () http://en.intelbras.com.br/downloads - Vendor Advisory | |
References | () https://medium.com/%40rsantos_14778/remote-control-cve-2019-20004-21f77e976715 - |
07 Nov 2023, 03:08
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2020-01-05 23:15
Updated : 2024-11-21 04:37
NVD link : CVE-2019-20004
Mitre link : CVE-2019-20004
CVE.ORG link : CVE-2019-20004
JSON object : View
Products Affected
intelbras
- iwr_3000n_firmware
- iwr_3000n
CWE
CWE-640
Weak Password Recovery Mechanism for Forgotten Password