All ADB broadband gateways / routers based on the Epicentro platform are affected by a privilege escalation vulnerability where attackers can gain access to the command line interface (CLI) if previously disabled by the ISP, escalate their privileges, and perform further attacks.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://www.sec-consult.com/en/blog/advisories/privilege-escalation-via-linux-group-manipulation-in-all-adb-broadband-gateways-routers/ | third party advisory exploit |
http://www.securityfocus.com/archive/1/542118/100/0/threaded | mailing list vdb entry third party advisory |
https://www.exploit-db.com/exploits/44984/ | exploit vdb entry third party advisory |
http://packetstormsecurity.com/files/148430/ADB-Group-Manipulation-Privilege-Escalation.html | exploit vdb entry third party advisory |
http://seclists.org/fulldisclosure/2018/Jul/19 | mailing list exploit third party advisory |