vendor:
DG860A NVRAM Backup
by:
Cosmo
7,5
CVSS
HIGH
Backup File World Readable Without Authentication
200
CWE
Product Name: DG860A NVRAM Backup
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
ARRIS DG860A NVRAM Backup ‘Compressor/Decompressor’
The ARRIS DG860A NVRAM Backup 'Compressor/Decompressor' vulnerability allows an attacker to access the router.data file without authentication, which contains password information in plain text. The backup file is world readable without authentication and contains password information in plain text.
Mitigation:
Ensure that the router.data file is not world readable and authentication is required to access the file.