CVE-2020-29669
In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password. This process has a vulnerability which can be used to take over the administrator account and results in shell access. As the admin user may read the /etc/shadow file, the password hashes of each user (including root) can be dumped. The root hash can be cracked easily which results in a complete system compromise.
Published:Dec 14, 2020
Last Modified:Nov 21, 2024
EPS:Dec 14, 2020
EPSS Score:0.10597
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Macally
Product
Wifisd2-2a82
Macally
Wifisd2-2a82
Vendor
Macally
Product
Wifisd2-2a82 Firmware
Macally
Wifisd2-2a82 Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
