surl.twcert.org.twConfirmation
http://surl.twcert.org.tw/5df6x CVE-2019-11061
CRITICAL
HG100 has a broken access control vulnerability in its Web API Server
Record summary
CVE-2019-11061 has a selected CVSS score of 10.0 (critical); EIP currently links 1 repository PoC.
Description
A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself via http://[target]/smarthome/devicecontrol without any authentication. CVSS 3.0 base score 10 (Confidentiality, Integrity and Availability impacts). CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
HG100 firmwareBrowse ASUS / HG100 firmware | CVE List | up to 4.00.0.6 | affected |
Proofs of concept
1Repository PoCs
GitHubtim124058/ASUS-SmartHome-ExploitRepository PoCby tim124058Stars: 23Not analyzed14 files
References
4github.comConfirmation
https://github.com/tim124058/ASUS-SmartHome-Exploit nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-11061 tvn.twcert.org.twConfirmation
https://tvn.twcert.org.tw/taiwanvn/TVN-201906003