CVE-2017-14244
CRITICALiBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 - Auth Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-14244. PoCs published by Gem George.
AI-analyzed exploit summary This is a writeup describing an authentication bypass vulnerability in iBall ADSL2+ Home Router. The vulnerability allows unauthenticated access to sensitive pages by appending '.cgi' to the URL, bypassing authentication.
Description
An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access administrative router settings by crafting URLs with a .cgi extension, as demonstrated by /info.cgi and /password.cgi.
Exploits (1)
This is a writeup describing an authentication bypass vulnerability in iBall ADSL2+ Home Router. The vulnerability allows unauthenticated access to sensitive pages by appending '.cgi' to the URL, bypassing authentication.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H