Security Features in RF 301K - #VU48737

 

Security Features in RF 301K - #VU48737

Published: December 1, 2020


Vulnerability identifier: #VU48737
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists du to improper permission validation. A remote attacker can send a specially crafted request to read and write to the RouterCfm.cfg file.


Affected software

RF 301K

Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins