vendor:
Secure WiFi Router
by:
Exploit Database
8.0
CVSS
HIGH
Command Injection
78
CWE
Product Name: Secure WiFi Router
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2018-5234
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: GNU/Linux
2018
PoC command injection in BLE service of Norton Core Secure WiFi Router (CVE-2018-5234)
This exploit is a proof-of-concept (PoC) command injection in the BLE service of Norton Core Secure WiFi Router. The exploit is demonstrated by using OS GNU/Linux, Bluetooth dongle adapter, and BlueZ utility. The exploit requires restarting the router to provide access to the engineering page, and then executing the PoC script as the root user with the command to be executed as an argument. After the script is successfully executed, the attacker can gain access to the device via SSH connection with root as the user and admin as the password.
Mitigation:
The vendor has released a patch to address this vulnerability.