Record summary

CVE-2019-11061 has a selected CVSS score of 10.0 (critical); EIP currently links 1 repository PoC.

Description

A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself via http://[target]/smarthome/devicecontrol without any authentication. CVSS 3.0 base score 10 (Confidentiality, Integrity and Availability impacts). CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE Listup to 4.00.0.6affected

Proofs of concept

1

Repository PoCs

GitHubtim124058/ASUS-SmartHome-ExploitRepository PoCby tim124058Stars: 23Not analyzed14 files

4.5 MiB · linked to 2 vulnerabilities

GitHub

PoC details

References

4