peter bassill · operator
$ cve CVE-2017-11435 JSON

CVE-2017-11435 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 10.1% (pctl 95)

Patch early

A public exploit exists.

Description

The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management console. The bug is exploitable remotely when the router is configured to expose the management console. The router is not validating the session token while returning answers for some methods in url '/api'. An attacker can use this vulnerability to retrieve sensitive information such as private/public IP addresses, SSID names, and passwords.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS10.05% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2017-07-19
Last modified2026-06-17

Affected (2)

VendorProduct
humaxdigitalhg100r
humaxdigitalhg100r firmware

Public exploits

SourceTitleDate
exploit-dbHumax Wi-Fi Router HG100R 2.0.6 - Authentication Bypass2017-09-14

References

→ the Explorer  ·  watch your stack  ·  NVD