Insufficient Compartmentalization in Edimax BR-6208AC V1 Devices
CVE-2019-13270
8.8HIGH
What is CVE-2019-13270?
Edimax BR-6208AC V1 devices exhibit a vulnerability due to insufficient compartmentalization between the host and guest networks. This issue arises when data is transferred between networks through the manipulation of IGMP groups. When a sender joins and then leaves an IGMP group, the router processes an IGMP Membership Query packet containing the Group IP. This packet is sent to both networks, allowing the sender complete control over the data transmitted within the Group IP field. This flaw can potentially lead to unauthorized access and exposure of sensitive information across network segments.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved