CVE Vulnerabilities

CVE-2021-20121

Published: Oct 11, 2021 | Modified: Oct 18, 2021
CVSS 3.x
4
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is vulnerable to an authenticated arbitrary file read. An authenticated user with physical access to the device can read arbitrary files from the device by preparing and connecting a specially prepared USB drive to the device, and making a series of crafted requests to the devices web interface.

Affected Software

Name Vendor Start Version End Version
Prv65b444a-s-ts_firmware Telus 3.00.20 (including) 3.00.20 (including)

References