An Insecure Permissions vulnerability in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to obtain sensitive information via SPI bus interface connected to pinout of the NAND flash memory.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
http://shenzhen.com | broken link |
http://zbt.com | vendor advisory |
https://blog.prodefense.io/zbt-we1626-wireless-router-cve-disclosures-b3534484d97d | third party advisory exploit |