Impact
The vulnerability arises from incorrect access control in the Proximus b-box router. It permits an authenticated user to disregard normal permission checks and modify the device’s port forwarding rules. This enables the attacker to open arbitrary ports, redirect traffic, or expose internal services, effectively allowing lateral movement or external access to the local network. The weakness is an improper access control and availability if the router is used as a barrier for a private network.
Affected Systems
Affected devices are Proximus b-box routers running firmware version 8c releases. The vulnerability is specific to this firmware and cannot be presumed to affect earlier or later builds until further analysis is available.
Risk and Exploitability
The CVSS v3.1 assessment indicates a high severity with a score of 8.1, reflecting local, authenticated, and high exploitation confidence. The EPSS score is <1%, indicating a very low but nonzero likelihood of exploitation. The vulnerability is not currently listed in the CISA KEV catalog, but its potential for exposing internal network services warrants immediate attention.
OpenCVE Enrichment