CVE-2005-1606

H-Sphere Winbox <2.4.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Morning Wood · textlocalwindows
https://www.exploit-db.com/exploits/25636

References (6)

Core 6
Core References
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/13559
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/20522
Patch third-party-advisory x_refsource_secunia
http://secunia.com/advisories/15287
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/16239

Scores

EPSS 0.0033
EPSS Percentile 56.1%

Details

Status published
Products (2)
positive_software/h-sphere_winbox 2.4.2_patch_4
positive_software/h-sphere_winbox 2.4.3_rc1
Published May 16, 2005
Tracked Since Feb 18, 2026