CVE ID | CVE-2018-1164 |
CVSS SCORE | 9.0, AV:N/AC:L/Au:S/C:C/I:C/A:C |
AFFECTED VENDORS |
ZyXEL |
AFFECTED PRODUCTS |
P-870H-51 DSL Router |
VULNERABILITY DETAILS |
The specific flaw exists within numerous exposed CGI endpoints. The vulnerability is caused by improper access controls that allow access to critical functions without authentication. An attacker can use this vulnerability to reboot affected devices, along with other actions. |
ADDITIONAL DETAILS |
06/21/17 - ZDI reported vulnerability to vendor -- Mitigation: |
DISCLOSURE TIMELINE |
|
CREDIT | Hubert WS Lin of Trend Micro |