Lucene search

K
cveMitreCVE-2019-14919
HistoryJan 09, 2020 - 5:15 p.m.

CVE-2019-14919

2020-01-0917:15:11
CWE-798
mitre
web.nvd.nist.gov
29
cve-2019-14919
telnet service
billion smart energy router
firmware v3.02.rc6
hardcoded credentials
local network attacker
root execution privileges

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

20.2%

An exposed Telnet Service on the Billion Smart Energy Router SG600R2 with firmware v3.02.rc6 allows a local network attacker to authenticate via hardcoded credentials into a shell, gaining root execution privileges over the device.

Affected configurations

Nvd
Node
billionsg600_r2_firmwareMatch3.02rc6
AND
billionsg600_r2Match-
VendorProductVersionCPE
billionsg600_r2_firmware3.02cpe:2.3:o:billion:sg600_r2_firmware:3.02:rc6:*:*:*:*:*:*
billionsg600_r2-cpe:2.3:h:billion:sg600_r2:-:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

20.2%

Related for CVE-2019-14919