[Japanese]
|
JVNDB-2017-000220
|
Multiple vulnerabilities in CG-WLR300NM
|
CG-WLR300NM provided by Corega Inc. is a wireless LAN router. CG-WLR300NM contains multiple vulnerabilities listed below.
Taizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V3 Severity: Base Metrics 6.8 (Medium) [IPA Score]
- Attack Vector: Adjacent Network
- Attack Complexity: Low
- Privileges Required: High
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
CVSS V2 Severity: Base Metrics 5.2 (Medium) [IPA Score]
- Access Vector: Adjacent Network
- Access Complexity: Low
- Authentication: Single Instance
- Confidentiality Impact: Partial
- Integrity Impact: Partial
- Availability Impact: Partial
The above CVSS base scores have been assigned for CVE-2017-10813.
|
CVSS V3 Severity:
Base Metrics:
6.8 (Medium) [IPA Score]
- Attack Vector: Adjacent
- Attack Complexity: Low
- Privileges Required: High
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
CVSS V2 Severity:Base Metrics:
5.2 (Medium)
[IPA Score]
- Access Vector: Adjacent Network
- Access Complexity: Low
- Authentication: Single
- Confidentiality Impact: Partial
- Integrity Impact: Partial
- Availability Impact: Partial
The above CVSS base scores have been assigned for CVE-2017-10814.
|
|
Corega Inc
- CG-WLR300NM firmware version 1.90 and earlier
|
|
* A user who can access the administrative console of the device may execute an arbitrary OS command - CVE-2017-10813
* A user who can access the administrative console of the device may execute arbitrary code - CVE-2017-10814
|
[Do not use CG-WLR300NM]
Stop using CG-WLR300NM. According to the developer, there is no plan to provide fix for these vulnerabilities since CG-WLR300NM is no longer supported.
|
Corega Inc
|
- Buffer Errors(CWE-119) [IPA Evaluation]
- OS Command Injection(CWE-78) [IPA Evaluation]
|
- CVE-2017-10813
- CVE-2017-10814
|
- JVN : JVN#00719891
- National Vulnerability Database (NVD) : CVE-2017-10813
- National Vulnerability Database (NVD) : CVE-2017-10814
|
- [2017/09/08]
Web page was published
- [2018/02/28]
References : Contents were added
|