The Uboot bootloader on the Verizon Wireless Network Extender SCS-26UC4 allows physically proximate attackers to obtain root access by connecting a crafted HDMI cable and using a sys session to modify the ramboot environment variable.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/BLUU-997M5B | us government resource |
http://www.kb.cert.org/vuls/id/458007 | third party advisory us government resource |
http://www.securityfocus.com/bid/61169 | vdb entry |