CVE-2024-53937
Last modified
CVE-2024-53937 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. An issue was discovered on Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by default with admin/admin as default credentials and is exposed over the LAN. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
An issue was discovered on Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by default with admin/admin as default credentials and is exposed over the LAN. The allows attackers to execute arbitrary commands with root-level permissions. Device setup does not require this password to be changed during setup in order to utilize the device. (However, the TELNET password is dictated by the current GUI password.)
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-53937?
How severe is CVE-2024-53937?
How do I fix CVE-2024-53937?
Are you affected by CVE-2024-53937?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
