CVE-2017-18373

Severity
8.8HIGH
EPSS
9.1%
top 7.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 2
Latest updateMay 24

Description

The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username user3 and and a long password consisting of a repetition of the string 0123456789. These accounts can be used to login to the web interface, exploit authenticated command injections, and change router settings for malicious purposes.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-46x2-283h-j6m2: The Billion 5200W-T TCLinux Fw $72022-05-24
CVEList
CVE-2017-18373: The Billion 5200W-T TCLinux Fw $72019-05-02
CVE-2017-18373 (HIGH CVSS 8.8) | The Billion 5200W-T TCLinux Fw $7.3 | cvebase.io