CVE-2017-6558 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 15.3% (pctl 97)
Patch early
A public exploit exists.
Description
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the password.cgi file.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 15.27% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-798 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-03-09 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| iball | ib-wra150n |
| iball | ib-wra150n firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | iBall Baton 150M Wireless Router - Authentication Bypass | 2017-03-07 |
References
→ the Explorer · watch your stack · NVD