Vulnerability Description
An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access administrative router settings by crafting URLs with a .cgi extension, as demonstrated by /info.cgi and /password.cgi.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Iball | Ib-Wra150N Firmware | fw_ib-lr7011a_1.0.2 |
| Iball | Ib-Wra150N | - |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/42740/Third Party AdvisoryVDB Entry
- https://www.techipick.com/iball-baton-adsl2-home-router-utstar-wa3002g4-adsl-broThird Party Advisory
- https://www.exploit-db.com/exploits/42740/Third Party AdvisoryVDB Entry
- https://www.techipick.com/iball-baton-adsl2-home-router-utstar-wa3002g4-adsl-broThird Party Advisory
FAQ
What is CVE-2017-14244?
CVE-2017-14244 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access administrative router settings by crafting URLs wit...
How severe is CVE-2017-14244?
CVE-2017-14244 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-14244?
Check the references section above for vendor advisories and patch information. Affected products include: Iball Ib-Wra150N Firmware, Iball Ib-Wra150N.