ZDI-21-683: Arlo Q Plus SSH Use of Hard-coded Credentials Privilege Escalation Vulnerability
This vulnerability allows attackers with physical access to escalate privileges on affected installations of Arlo Q Plus. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSH service. The device can be booted into a special operation mode where hard-coded credentials are accepted for SSH authentication. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-21-683?
ZDI-21-683 is categorized with a high severity due to its potential for privilege escalation without authentication.
How do I fix ZDI-21-683?
To mitigate ZDI-21-683, ensure you apply the latest firmware updates provided by Arlo.
What kind of access is required to exploit ZDI-21-683?
Exploitation of ZDI-21-683 requires physical access to the affected Arlo Q Plus device.
What vulnerable feature does ZDI-21-683 affect?
ZDI-21-683 affects the SSH service of the Arlo Q Plus, allowing for privilege escalation.
Is authentication necessary for exploiting ZDI-21-683?
No, ZDI-21-683 can be exploited without any required authentication.