vendor:
Wireless Router
by:
Adithyan AK
9.8
CVSS
CRITICAL
Password Reset
287
CWE
Product Name: Wireless Router
Affected Version From: Coship RT3052 - 4.0.0.48
Affected Version To: Coship RT7620 - 10.0.0.49
Patch Exists: YES
Related CWE: CVE-2019-7564
CPE: h:coship:rt3052
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: MacOS Mojave v.10.14
2019
Coship Wireless Router – Wireless SSID Unauthenticated Password Reset
A vulnerability in Coship Wireless Routers allows an unauthenticated attacker to reset the password of the Wireless SSID to 'password'. This is done by sending a POST request to the router's gateway address with the parameters specified in the exploit code. The affected versions are Coship RT3052 - 4.0.0.48, Coship RT3050 - 4.0.0.40, Coship WM3300 - 5.0.0.54, Coship WM3300 - 5.0.0.55, Coship RT7620 - 10.0.0.49.
Mitigation:
Users should update their routers to the latest version available and ensure that the router is configured with a strong password.