CVE-2017-6558
Last modified
CVE-2017-6558 is a vulnerability of currently unknown severity. iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the password.cgi file.. EPSS estimates a 15.27% chance of exploitation in the next 30 days.
Description
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the password.cgi file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Iball | Ib-Wra150n Firmware | 1.2.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-6558?
How severe is CVE-2017-6558?
How do I fix CVE-2017-6558?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-6552Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 devices have an insu…
- CVE-2017-6553Buffer Overflow in Quest One Identity Privilege Manager for …
- CVE-2017-6554pmmasterd in Quest Privilege Manager before 6.0.0.061, when …
- CVE-2017-6555Cross-site scripting (XSS) vulnerability in /admin/moduleint…
- CVE-2017-6556Cross-site scripting (XSS) vulnerability in CMS Made Simple …
- CVE-2017-6557SQL injection vulnerability in ArrayOS before AG 9.4.0.135, …
- CVE-2017-6559XSS in Agora-Project 3.2.2 exists with an index.php?disconne…
- CVE-2017-6560XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=mis…
- CVE-2017-6561XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=obj…
- CVE-2017-6562XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=fil…
- CVE-2017-6564On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, t…
- CVE-2017-6565On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, t…
Are you affected by CVE-2017-6558?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
