An issue was discovered on Intex N150 devices. The backup/restore option does not check the file extension uploaded for importing a configuration files backup, which can lead to corrupting the router firmware settings or even the uploading of malicious files. In order to exploit the vulnerability, an attacker can upload any malicious file and force reboot the router with it.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-07-02T16:00:00

Updated: 2024-08-05T08:38:06.214Z

Reserved: 2018-06-18T00:00:00

Link: CVE-2018-12528

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-07-02T16:29:00.350

Modified: 2018-09-05T13:03:36.597

Link: CVE-2018-12528

cve-icon Redhat

No data.