First published: Sun Jan 05 2020(Updated: )
An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete control of the router.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Intelbras Iwr 3000n Firmware | =1.8.7 | |
Intelbras IWR 3000N |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20004 is a vulnerability found on Intelbras IWR 3000N 1.8.7 devices that allows unauthorized access to the router.
The severity of CVE-2019-20004 is high, with a CVSS score of 8.8.
CVE-2019-20004 allows an attacker to gain complete control of the router by exploiting a flaw in the password change mechanism.
To fix CVE-2019-20004, it is recommended to update the firmware of the Intelbras IWR 3000N device to version 1.8.7 or later.
You can find more information about CVE-2019-20004 on the Intelbras website and a detailed write-up on the vulnerability on Medium.