CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2020-11965

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0540%
EPSS Percentile40.55th
Published2020年4月21日
Last Modified2024年11月21日

Vulnerability Description

In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for any unconfigured release of OpenWRT, and true of many other new Linux distros prior to being configured for the first time”

Affected Platforms (CPE)

💻
Evenroute

Iqrouter Firmware

<= 3.3.1

References & Advisories

相關漏洞威脅