Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.
History

Wed, 25 Sep 2024 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Hathway
Hathway skyworth Cm5100-511
Hathway skyworth Cm5100-511 Firmware
Weaknesses CWE-522
CPEs cpe:2.3:h:hathway:skyworth_cm5100-511:-:*:*:*:*:*:*:*
cpe:2.3:o:hathway:skyworth_cm5100-511_firmware:4.1.1.24:*:*:*:*:*:*:*
Vendors & Products Hathway
Hathway skyworth Cm5100-511
Hathway skyworth Cm5100-511 Firmware

Tue, 10 Sep 2024 21:30:00 +0000

Type Values Removed Values Added
Description An issue in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain sensitive information via SPI flash Firmware W25Q64JV Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.
First Time appeared Skyworthdigital
Skyworthdigital cm5100 Firmware
Weaknesses CWE-256
CPEs cpe:2.3:o:skyworthdigital:cm5100_firmware:4.1.1.24:*:*:*:*:*:*:*
Vendors & Products Skyworthdigital
Skyworthdigital cm5100 Firmware
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Description An issue in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain sensitive information via SPI flash Firmware W25Q64JV
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-09-10T00:00:00

Updated: 2024-09-10T21:11:56.393560

Reserved: 2024-08-21T00:00:00

Link: CVE-2024-44815

cve-icon Vulnrichment

Updated: 2024-09-10T20:21:15.169Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-10T16:15:20.453

Modified: 2024-09-25T19:17:02.237

Link: CVE-2024-44815

cve-icon Redhat

No data.