HIGH · 7.5

CVE-2018-13109

All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able to access and manipulate settings within the web int...

Vulnerability Description

All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able to access and manipulate settings within the web interface that are forbidden to end users (e.g., by the ISP). An attacker would be able to enable the TELNET server or other settings as well.

CVSS Score

7.5

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
AdbglobalDv2210 Firmware-
AdbglobalDv2210-
AdbglobalVv2220 Firmware-
AdbglobalVv2220-
AdbglobalVv5522 Firmware-
AdbglobalVv5522-
AdbglobalPrg Av4202N Firmware-
AdbglobalPrg Av4202N-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-13109?

CVE-2018-13109 is a vulnerability with a CVSS score of 7.5 (HIGH). All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able to access and manipulate settings within the web int...

How severe is CVE-2018-13109?

CVE-2018-13109 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-13109?

Check the references section above for vendor advisories and patch information. Affected products include: Adbglobal Dv2210 Firmware, Adbglobal Dv2210, Adbglobal Vv2220 Firmware, Adbglobal Vv2220, Adbglobal Vv5522 Firmware.