20180109 FiberHome MIFI LM53Q1 Multiple Vulnerabilitiesmailing list
http://seclists.org/fulldisclosure/2018/Jan/28 CVE-2017-16885
CRITICAL
FiberHome LM53Q1 - Multiple Vulnerabilities
Record summary
CVE-2017-16885 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Changing Passwords, etc.) allows remote attackers to look for the information without authenticating. The information includes Version of device, Firmware ID, Connected users to device along their MAC Addresses, etc.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFiberHome LM53Q1 - Multiple VulnerabilitiesExploitDB exploitby Ibad ShahNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-16885 43460exploit
https://www.exploit-db.com/exploits/43460