CVE-2018-9149
PoC —CVSS 3.0
6.8 medium
EPSS
<1%p39
Published
()
Modified
Description
The Zyxel Multy X (AC3000 Tri-Band WiFi System) device doesn't use a suitable mechanism to protect the UART. After an attacker dismantles the device and uses a USB-to-UART cable to connect the device, he can use the 1234 password for the root account to login to the system. Furthermore, an attacker can start the device's TELNET service as a backdoor.
- Vendors
- zyxel
- Products
- ac3000 firmware
- Weakness
- CWE-798
- Vector
- CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.