CVE-2024-40087

CRITICAL

Vilo 5 Mesh WiFi System <= 5.16.1.33 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Insecure Permissions. Lack of authentication in the custom TCP service on port 5432 allows remote, unauthenticated attackers to gain administrative access over the router.

Scores

CVSS v3 9.6
EPSS 0.0100
EPSS Percentile 77.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-306
Status published
Products (1)
viloliving/vilo_5_firmware < 5.16.1.33
Published Oct 21, 2024
Tracked Since Feb 18, 2026