ZDI-CAN-12890: Arlo Q Plus SSH Use of Hard-coded Credentials Privilege Escalation Vulnerability
This vulnerability allows attackers with physical access to escalate privileges on affected installations of Arlo Q Plus. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSH service. The device can be booted into a special operation mode where hard-coded credentials are accepted for SSH authentication. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-12890?
The ZDI-CAN-12890 vulnerability is considered to have a high severity due to its privilege escalation capabilities.
How do I fix ZDI-CAN-12890?
To fix ZDI-CAN-12890, it is recommended to update the Arlo Q Plus firmware to the latest version that addresses this vulnerability.
What type of access is required to exploit ZDI-CAN-12890?
Exploitation of ZDI-CAN-12890 requires physical access to the affected Arlo Q Plus device.
What component is affected by ZDI-CAN-12890?
The SSH service is the specific component affected by the ZDI-CAN-12890 vulnerability.
Is authentication required to exploit ZDI-CAN-12890?
No, authentication is not required to exploit the ZDI-CAN-12890 vulnerability.