CVE-2020-35757 Information
Jun 07, 2022
cve
Description
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is Unauthenticated Root ADB Access Over TCP. The LS9 web interface provides functionality to access ADB over TCP. This is not enabled by default but can be enabled by sending a crafted request to a web management interface endpoint. Requests made to this endpoint do not require authentication. As such any unauthenticated user who is able to access the web interface will be able to gain root privileges on the LS9 module.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://www.iot-inspector.com/blog/advisory-multiple-issues-libre-wireless-ls9/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: