vendor:
NuCom 11N Wireless Router
by:
LiquidWorm
N/A
CVSS
N/A
Remote Privilege Escalation
Unknown
CWE
Product Name: NuCom 11N Wireless Router
Affected Version From: 5.07.72_multi_NCM01
Affected Version To: 5.07.90_multi_NCM01
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: GoAhead-Webs, Tenda
2021
NuCom 11N Wireless Router 5.07.90 – Remote Privilege Escalation
The non-privileged default user can elevate his/her privileges by sending a HTTP GET request to the configuration backup endpoint and disclose the http super password (admin credentials) in Base64 encoded value. Once authenticated as admin, an attacker will be granted access to the additional and privileged pages.
Mitigation:
Unknown