CVE-2018-20008

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
28/05/2019
Last modified:
21/06/2021

Description

iBall Baton iB-WRB302N20122017 devices have improper access control over the UART interface, allowing physical attackers to discover Wi-Fi credentials (plain text) and the web-console password (base64) via the debugging console.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:iball:ib-wrb302n_firmware:ib-wrb302n20122017:*:*:*:*:*:*:*
cpe:2.3:h:iball:ib-wrb302n:-:*:*:*:*:*:*:*