CVE-2018-17873

HIGH

WiFiRanger <7.0.8rc3 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-17873. PoCs published by Luct0r.

AI-analyzed exploit summary This exploit leverages anonymous FTP access to retrieve a private SSH key from vulnerable WiFiRanger routers, then uses it to log in as root. The script automates the process of downloading the key and establishing an SSH session.

Description

An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 and earlier allows an attacker with adjacent network access to read the SSH Private Key and log in to the root account.

Exploits (1)

nomisec WORKING POC 1 stars
by Luct0r · poc
https://github.com/Luct0r/CVE-2018-17873

This exploit leverages anonymous FTP access to retrieve a private SSH key from vulnerable WiFiRanger routers, then uses it to log in as root. The script automates the process of downloading the key and establishing an SSH session.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: WiFiRanger indoor/outdoor routers (Core, GoAC, Sky Pro, EliteAC, EliteAC FM) firmware version 7.0.8rc3 and earlier
No auth needed
Prerequisites: adjacent network access to the target router · FTP service exposed on the target · SSH service exposed on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0185
EPSS Percentile 76.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (1)
wifiranger/wifiranger_firmware < 7.0.8
Published Oct 23, 2018
Tracked Since Feb 18, 2026