HIGH

CVE-2020-29669

CVSS v3

8.8

HIGH

EPSS Score

10.6%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password. This process has a vulnerability which can be used to take over the administrator account and results in shell access. As the admin user may read the /etc/shadow file, the password hashes of each user (including root) can be dumped. The root hash can be cracked easily which results in a complete system compromise.

Technical details

Published
12/14/2020

Frequently asked questions

What is CVE-2020-29669?

In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password. This process has a vulnerability which can be used to take over the administrator account and results in shell access. As the admin user may read the /etc/shadow file, the password hashes of each user (including root) can be dumped. The root hash can be cracked easily which results in a complete system compromise.

Is CVE-2020-29669 actively exploited?

Active exploitation of CVE-2020-29669 has not been confirmed. The EPSS score is 10.6%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-29669?

CVE-2020-29669 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2020-29669 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.