CyberSec.Space Logo
CVEブラウザに戻る

CVE-2020-11967

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0620%
EPSS Percentile8.04th
Published2020年4月21日
Last Modified2024年11月21日

Vulnerability Description

In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for any unconfigured release of OpenWRT, and true of many other new Linux distros prior to being configured for the first time”

Affected Platforms (CPE)

💻
Evenroute

Iqrouter Firmware

<= 3.3.1

References & Advisories

関連する脆弱性情報