Vulnerability Description
SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) to access the TELNET service, allowing attackers to erase/read/write the firmware remotely.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sooteway Wi-Fi Range Extender Project | Sooteway Wi-Fi Range Extender | 1.5 |
Related Weaknesses (CWE)
References
- https://blog-ssh3ll.medium.com/acexy-wireless-n-wifi-repeater-vulnerabilities-8bExploitThird Party Advisory
- https://www.amazon.it/SOOTEWAY-Ripetitore-Extender-Wireless-Wmplificatore/dp/B08Product
- https://blog-ssh3ll.medium.com/acexy-wireless-n-wifi-repeater-vulnerabilities-8bExploitThird Party Advisory
- https://www.amazon.it/SOOTEWAY-Ripetitore-Extender-Wireless-Wmplificatore/dp/B08Product
FAQ
What is CVE-2021-30028?
CVE-2021-30028 is a vulnerability with a CVSS score of 7.2 (HIGH). SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) to access the TELNET service, allowing attackers to erase/read/write the firmwar...
How severe is CVE-2021-30028?
CVE-2021-30028 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-30028?
Check the references section above for vendor advisories and patch information. Affected products include: Sooteway Wi-Fi Range Extender Project Sooteway Wi-Fi Range Extender.