Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
RACOM M!DGE2 Privilege Escalation via SDK Testing Endpoint
Vulnerability Description
A non-primary administrator user with admin rights to the web interface but without shell access permissions can display configuration of the device including the master admin password. This vulnerability also allows the user to give themselves shell access with the root gid.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
特权管理不恰当
Vulnerability Title
RACOM M!DGE2 安全漏洞
Vulnerability Description
RACOM M!DGE2是捷克RACOM公司的一款蜂窝网络路由器。 RACOM M!DGE2存在安全漏洞,该漏洞源于非主管理员用户可显示设备配置包括主管理员密码,可能导致权限提升。
CVSS Information
N/A
Vulnerability Type
N/A