httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the unauthenticated setup3.htm endpoint from the local network.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://cerne.xyz/bugs/CVE-2020-8798.html | third party advisory exploit |