peter bassill · operator
$ cve CVE-2018-13109 JSON

CVE-2018-13109 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 35.5% (pctl 98)

Patch early

A public exploit exists.

Description

All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able to access and manipulate settings within the web interface that are forbidden to end users (e.g., by the ISP). An attacker would be able to enable the TELNET server or other settings as well.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS35.48% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-863
On CISA KEVno
Public exploityes
Published2018-07-06
Last modified2026-06-17

Affected (8)

VendorProduct
adbglobaldv2210
adbglobaldv2210 firmware
adbglobalprg av4202n
adbglobalprg av4202n firmware
adbglobalvv2220
adbglobalvv2220 firmware
adbglobalvv5522
adbglobalvv5522 firmware

Public exploits

SourceTitleDate
exploit-dbADB Broadband Gateways / Routers - Authorization Bypass2018-07-05

References

→ the Explorer  ·  watch your stack  ·  NVD