Improper access control in TP-Link Omada ER605



Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2024-1180
CWE-ID CWE-284
Exploitation vector Local network
Public exploit N/A
Vulnerable software
Omada ER605
Hardware solutions / Routers & switches, VoIP, GSM, etc

Vendor TP-Link

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Improper access control

EUVDB-ID: #VU86168

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-1180

CWE-ID: CWE-284 - Improper Access Control

Exploit availability: No

Description

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper handling of the name field in the access control user interface. A remote administrator on the local network can bypass implemented security restrictions and execute arbitrary code on the target system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Omada ER605: before 2_2.2.3 Build 20231201

CPE2.3 External links

http://www.zerodayinitiative.com/advisories/ZDI-24-086/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the local network (LAN).

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###