10
CVSSv2

CVE-2019-9160

Published: 18/04/2019 Updated: 19/04/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and previous versions has a backdoor account allowing a remote malicious user to login to the system via SSH (on TCP port 22345) and escalate to root (because the password for root is the WebUI admin password concatenated with a static string).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xinruidz sundray_wan_controller_firmware