Vulnerability Description
HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in the mac parameter of a protocol.csp?function=set&fname=security&opt=mac_table request.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hootoo | Tripmate Titan Ht-Tm05 Firmware | 2.000.022 |
| Hootoo | Tripmate Titan Ht-Tm05 | - |
Related Weaknesses (CWE)
References
- https://ioactive.com/hootoo-tripmate-routers-are-cute-but/ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/46143ExploitThird Party AdvisoryVDB Entry
- https://ioactive.com/hootoo-tripmate-routers-are-cute-but/ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/46143ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2018-20841?
CVE-2018-20841 is a vulnerability with a CVSS score of 9.8 (CRITICAL). HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in the mac parameter of a protocol.csp?function=set&fname=...
How severe is CVE-2018-20841?
CVE-2018-20841 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-20841?
Check the references section above for vendor advisories and patch information. Affected products include: Hootoo Tripmate Titan Ht-Tm05 Firmware, Hootoo Tripmate Titan Ht-Tm05.