An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. An ability exists for an unauthenticated user to browse a confidential ui/1.0.99.187766/dynamic/js/setup.js.localized file on the router's webserver, allowing for an attacker to identify possible passwords that the system uses to set the default guest network password. An attacker can use this list of 30 words along with a random 2 digit number to brute force their access onto a router's guest network.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-06-17T18:26:48
Updated: 2024-08-04T20:54:28.305Z
Reserved: 2019-02-07T00:00:00
Link: CVE-2019-7579
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-06-17T19:15:11.783
Modified: 2024-11-21T04:48:22.050
Link: CVE-2019-7579
Redhat
No data.