peter bassill · operator
$ cve CVE-2017-16885 JSON

CVE-2017-16885 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 33.5% (pctl 98)

Patch early

A public exploit exists.

Description

Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Changing Passwords, etc.) allows remote attackers to look for the information without authenticating. The information includes Version of device, Firmware ID, Connected users to device along their MAC Addresses, etc.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS33.45% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-732
On CISA KEVno
Public exploityes
Published2018-01-12
Last modified2026-06-17

Affected (2)

VendorProduct
fiberhomelm53q1
fiberhomelm53q1 firmware

Public exploits

SourceTitleDate
exploit-dbFiberHome LM53Q1 - Multiple Vulnerabilities2018-01-08

References

→ the Explorer  ·  watch your stack  ·  NVD