CVE-2018-13109 EXPLOIT
7.5
HIGH · CVSS 3.0 · EPSS 35.5% (pctl 98)
Patch early
A public exploit exists.
Description
All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able to access and manipulate settings within the web interface that are forbidden to end users (e.g., by the ISP). An attacker would be able to enable the TELNET server or other settings as well.
Scoring
| CVSS | 7.5 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
| EPSS | 35.48% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-863 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-07-06 |
| Last modified | 2026-06-17 |
Affected (8)
| Vendor | Product |
|---|---|
| adbglobal | dv2210 |
| adbglobal | dv2210 firmware |
| adbglobal | prg av4202n |
| adbglobal | prg av4202n firmware |
| adbglobal | vv2220 |
| adbglobal | vv2220 firmware |
| adbglobal | vv5522 |
| adbglobal | vv5522 firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ADB Broadband Gateways / Routers - Authorization Bypass | 2018-07-05 |
References
- http://packetstormsecurity.com/files/148429/ADB-Authorization-Bypass.html
- http://seclists.org/fulldisclosure/2018/Jul/18
- http://www.securityfocus.com/archive/1/542119/100/0/threaded
- https://www.exploit-db.com/exploits/44982/
- https://www.sec-consult.com/en/blog/advisories/authorization-bypass-in-all-adb-broadband-gateways-routers/
- http://packetstormsecurity.com/files/148429/ADB-Authorization-Bypass.html
- http://seclists.org/fulldisclosure/2018/Jul/18
- http://www.securityfocus.com/archive/1/542119/100/0/threaded
- https://www.exploit-db.com/exploits/44982/
- https://www.sec-consult.com/en/blog/advisories/authorization-bypass-in-all-adb-broadband-gateways-routers/
→ the Explorer · watch your stack · NVD