lg.pl in Cistron-LG 1.01 stores sensitive information under the web root with insufficient access controls, which allows remote attackers to obtain IP addresses and other unspecified router credentials.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www.s3.eurecom.fr/cve/CVE-2014-3930.txt | third party advisory |
https://hackerone.com/reports/16330 | third party advisory |