Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 25 Sep 2024 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Hathway
Hathway skyworth Cm5100-511
Hathway skyworth Cm5100-511 Firmware
Weaknesses CWE-522
CPEs cpe:2.3:h:hathway:skyworth_cm5100-511:-:*:*:*:*:*:*:*
cpe:2.3:o:hathway:skyworth_cm5100-511_firmware:4.1.1.24:*:*:*:*:*:*:*
Vendors & Products Hathway
Hathway skyworth Cm5100-511
Hathway skyworth Cm5100-511 Firmware

Tue, 10 Sep 2024 21:30:00 +0000

Type Values Removed Values Added
Description An issue in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain sensitive information via SPI flash Firmware W25Q64JV Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.
First Time appeared Skyworthdigital
Skyworthdigital cm5100 Firmware
Weaknesses CWE-256
CPEs cpe:2.3:o:skyworthdigital:cm5100_firmware:4.1.1.24:*:*:*:*:*:*:*
Vendors & Products Skyworthdigital
Skyworthdigital cm5100 Firmware
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Description An issue in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain sensitive information via SPI flash Firmware W25Q64JV
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-10T21:11:56.393560

Reserved: 2024-08-21T00:00:00

Link: CVE-2024-44815

cve-icon Vulnrichment

Updated: 2024-09-10T20:21:15.169Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-10T16:15:20.453

Modified: 2024-09-25T19:17:02.237

Link: CVE-2024-44815

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.