CVE-2020-12773: Realtek ADSL/PON Modem SoC - Security Misconfiguration
Published Jun 8, 2020
·Updated
A security misconfiguration vulnerability exists in the SDK of some Realtek ADSL/PON Modem SoC firmware, which allows attackers using a default password to execute arbitrary commands remotely via the build-in network monitoring tool.
Affected Software
1 affected component
Realtek Adsl Router Soc Firmware
Remediation
Information
Contact Realtek Semi. Corp. for mitigation.
Event History
Jun 8, 2020
CVE Published
via MITRE·07:20 AM
Data Sourced
via MITRE·07:20 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this security misconfiguration vulnerability?
The vulnerability ID for this security misconfiguration vulnerability is CVE-2020-12773.
2
What is the severity of CVE-2020-12773?
The severity of CVE-2020-12773 is critical with a score of 8.8.
3
What is affected by CVE-2020-12773?
The Realtek ADSL/PON Modem SoC firmware is affected by CVE-2020-12773.
4
How can attackers exploit CVE-2020-12773?
Attackers can exploit CVE-2020-12773 by using a default password to execute arbitrary commands remotely via the build-in network monitoring tool.
5
Is there a fix available for CVE-2020-12773?
It is recommended to update the affected Realtek ADSL/PON Modem SoC firmware to the latest version to fix CVE-2020-12773.