vendor:
DIGISOL DG-HR1400
by:
Indrajith.A.N
8,8
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: DIGISOL DG-HR1400
Affected Version From: <=1.00.02
Affected Version To: <=1.00.02
Patch Exists: YES
Related CWE: CVE-2017-6896
CPE: h:digisol:dg-hr1400
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
Cookie based privilege escalation in DIGISOL DG-HR1400 1.00.02 wireless router.
A privilege escalation vulnerability in the DIGISOL DG-HR1400 wireless router enables an attacker escalate his user privilege to an admin just by modifying the Base64encoded session cookie value.
Mitigation:
The vendor has released a patch to address this vulnerability.