Remote Information Disclosure in Technicolor TC7110.B Devices
CVE-2018-20442

9.8CRITICAL

Key Information:

Vendor
CVE Published:
25 December 2018

What is CVE-2018-20442?

The Technicolor TC7110.B STC8.62.02 devices are susceptible to a security flaw that allows remote attackers to extract sensitive Wi-Fi credentials. By sending specific SNMP requests, such as iso.3.6.1.4.1.2863.205.10.1.30.4.1.14.1.3.32 and iso.3.6.1.4.1.2863.205.10.1.30.4.2.4.1.2.32, unauthorized individuals can gain access to crucial network information, potentially compromising the security of the Wi-Fi network. It is essential to apply recommended patches and implement security measures to protect these devices from potential exploitation.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.