CVE-2019-13140
Last modified
CVE-2019-13140 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the "user" account to extract the 3DES key via JSON commands to ubus. The 3DES key is used to decrypt the provisioning file provided by Adamo Telecom on a public URL via cleartext HTTP.. EPSS estimates a 2.04% chance of exploitation in the next 30 days.
Description
Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the "user" account to extract the 3DES key via JSON commands to ubus. The 3DES key is used to decrypt the provisioning file provided by Adamo Telecom on a public URL via cleartext HTTP.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intenogroup | Eg200 Firmware | eg200-wu7p1u_adamo3.16.4-190226_1650 |
References
- http://packetstormsecurity.com/files/154494/Inteno-IOPSYS-Gateway-3DES-Key-Extraction-Improper-Access.htmlExploit, Third Party Advisory, VDB Entry
- https://twitter.com/GerardFuguet/status/1169298861782896642Third Party Advisory
- https://www.exploit-db.com/docs/47397Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/47390Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/154494/Inteno-IOPSYS-Gateway-3DES-Key-Extraction-Improper-Access.htmlExploit, Third Party Advisory, VDB Entry
- https://twitter.com/GerardFuguet/status/1169298861782896642Third Party Advisory
- https://www.exploit-db.com/docs/47397Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/47390Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-13140?
How severe is CVE-2019-13140?
How do I fix CVE-2019-13140?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-13134ImageMagick before 7.0.8-50 has a memory leak vulnerability …5.5
- CVE-2019-13135ImageMagick before 7.0.8-50 has a "use of uninitialized valu…8.8
- CVE-2019-13136ImageMagick before 7.0.8-50 has an integer overflow vulnerab…
- CVE-2019-13137ImageMagick before 7.0.8-50 has a memory leak vulnerability …6.5
- CVE-2019-13139In Docker before 18.09.4, an attacker who is capable of supp…
- CVE-2019-1314A security feature bypass vulnerability exists in Windows 10…6.8
- CVE-2019-13142The RzSurroundVADStreamingService (RzSurroundVADStreamingSer…
- CVE-2019-13143An HTTP parameter pollution issue was discovered on Shenzhen…
- CVE-2019-13144myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection. This is…9.8
- CVE-2019-13145Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-13146The field_test gem 0.3.0 for Ruby has unvalidated input. A m…
- CVE-2019-13147In Audio File Library (aka audiofile) 0.3.6, there exists on…6.5
Are you affected by CVE-2019-13140?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
