4
CVSSv2

CVE-2019-13140

Published: 16/09/2019 Updated: 31/03/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the "user" account to extract the 3DES key via JSON commands to ubus. The 3DES key is used to decrypt the provisioning file provided by Adamo Telecom on a public URL via cleartext HTTP.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

intenogroup eg200_firmware eg200-wu7p1u_adamo3.16.4-190226_1650

Exploits

Inteno EG200 routers with firmware versions EG200-WU7P1U_ADAMO3164-190226_1650 and below have a JUCI ACL misconfiguration that allows the "user" account to extract the 3DES key via JSON commands to ubus The 3DES key is used to decrypt the provisioning file provided by Adamo Telecom on a public URL via cleartext HTTP ...