20180109 FiberHome MIFI LM53Q1 Multiple Vulnerabilitiesmailing list
http://seclists.org/fulldisclosure/2018/Jan/28 CVE-2017-16887
CRITICAL
FiberHome LM53Q1 - Multiple Vulnerabilities
Record summary
CVE-2017-16887 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services can result in disclosure of the WLAN key/password.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFiberHome LM53Q1 - Multiple VulnerabilitiesExploitDB exploitby Ibad ShahNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-16887 43460exploit
https://www.exploit-db.com/exploits/43460