vendor:
AN1020-25
by:
Ibad Shah
9,8
CVSS
CRITICAL
Bypass authentication and gain unauthorized access vulnerability
287
CWE
Product Name: AN1020-25
Affected Version From: AN1020-25
Affected Version To: AN1020-25
Patch Exists: Yes
Related CWE: CVE-2017-14147
CPE: h:fiberhome:an1020-25
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
FiberHome Unauthenticated ADSL Router Factory Reset.
This vulnerability in AN1020-25 router enables an anonymous unauthorized attacker to bypass authentication & access Resetting Router to Factory Settings, resulting in un-authorized operation & resetting it to Factory state. It later allows attacker to login to Router's Main Page with default username & password.
Mitigation:
FiberHome has released a patch to address this vulnerability.