Insufficient Compartmentalization in Edimax BR-6208AC V1 Devices
CVE-2019-13270

8.8HIGH

Key Information:

Vendor

Edimax

Vendor
CVE Published:
27 August 2019

What is CVE-2019-13270?

Edimax BR-6208AC V1 devices exhibit a vulnerability due to insufficient compartmentalization between the host and guest networks. This issue arises when data is transferred between networks through the manipulation of IGMP groups. When a sender joins and then leaves an IGMP group, the router processes an IGMP Membership Query packet containing the Group IP. This packet is sent to both networks, allowing the sender complete control over the data transmitted within the Group IP field. This flaw can potentially lead to unauthorized access and exposure of sensitive information across network segments.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.