Skip to content

WiFiRanger 7.0.8rc3 Incorrect Access Control - Privilege Escalation

License

Notifications You must be signed in to change notification settings

Luct0r/CVE-2018-17873

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 
 
 

Repository files navigation

CVE-2018-17873

WiFiRanger indoor routers (Core, GoAC) and their outdoor paired routers (Sky Pro, EliteAC, EliteAC FM) running firmware version 7.0.8rc3 and earlier allow anonymous FTP read/write access and have left the SSH Private Key in the clear - making it a trivial task to view/copy the key and log in with root privileges.

Adjacent network access required to exploit this vulnerability.

Exploit:

Extremely simple shell script that grabs the private key and logs in as root.

Usage:

./wifiRangerPwn.sh <WiFiRanger IP>

About

WiFiRanger 7.0.8rc3 Incorrect Access Control - Privilege Escalation

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages