CyberSec.Space Logo
Back to CVE Browser

CVE-2020-11965

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0540%
EPSS Percentile40.55th
PublishedApr 21, 2020
Last ModifiedNov 21, 2024

Vulnerability Description

In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is โ€œtrue for any unconfigured release of OpenWRT, and true of many other new Linux distros prior to being configured for the first timeโ€

Affected Platforms (CPE)

๐Ÿ’ป
Evenroute

Iqrouter Firmware

<= 3.3.1

References & Advisories

Related Vulnerabilities