20180109 FiberHome MIFI LM53Q1 Multiple Vulnerabilitiesmailing list
http://seclists.org/fulldisclosure/2018/Jan/28 CVE-2017-16886
HIGH
FiberHome LM53Q1 - Multiple Vulnerabilities
Record summary
CVE-2017-16886 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFiberHome LM53Q1 - Multiple VulnerabilitiesExploitDB exploitby Ibad ShahNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-16886 43460exploit
https://www.exploit-db.com/exploits/43460