Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-17873. PoCs published by Luct0r.
AI-analyzed exploit summary This exploit leverages anonymous FTP access to retrieve a private SSH key from vulnerable WiFiRanger routers, then uses it to log in as root. The script automates the process of downloading the key and establishing an SSH session.
Description
An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 and earlier allows an attacker with adjacent network access to read the SSH Private Key and log in to the root account.
Exploits (1)
This exploit leverages anonymous FTP access to retrieve a private SSH key from vulnerable WiFiRanger routers, then uses it to log in as root. The script automates the process of downloading the key and establishing an SSH session.
References (1)
Scores
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H