890
VMScore

CVE-2018-15557

Published: 27/06/2019 Updated: 24/08/2020
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists in the Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 devices. An attacker can statically set his/her IP to anything on the 169.254.1.0/24 subnet, and obtain root access by connecting to 169.254.1.2 port 23 with telnet/netcat.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

actiontec web6000q_firmware 1.1.02.22

Exploits

Telus Actiontec WEB6000Q with firmware 110222 suffers from both local and remote privilege escalation vulnerabilities ...