Description
Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.
Published: 2024-09-10
Score: 8 High
EPSS: 10.8% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 25 Sep 2024 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Hathway
Hathway skyworth Cm5100-511
Hathway skyworth Cm5100-511 Firmware
Weaknesses CWE-522
CPEs cpe:2.3:h:hathway:skyworth_cm5100-511:-:*:*:*:*:*:*:*
cpe:2.3:o:hathway:skyworth_cm5100-511_firmware:4.1.1.24:*:*:*:*:*:*:*
Vendors & Products Hathway
Hathway skyworth Cm5100-511
Hathway skyworth Cm5100-511 Firmware

Tue, 10 Sep 2024 21:30:00 +0000

Type Values Removed Values Added
Description An issue in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain sensitive information via SPI flash Firmware W25Q64JV Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.
First Time appeared Skyworthdigital
Skyworthdigital cm5100 Firmware
Weaknesses CWE-256
CPEs cpe:2.3:o:skyworthdigital:cm5100_firmware:4.1.1.24:*:*:*:*:*:*:*
Vendors & Products Skyworthdigital
Skyworthdigital cm5100 Firmware
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Description An issue in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain sensitive information via SPI flash Firmware W25Q64JV
References

Subscriptions

Hathway Skyworth Cm5100-511 Skyworth Cm5100-511 Firmware
Skyworthdigital Cm5100 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-10T21:11:56.393Z

Reserved: 2024-08-21T00:00:00.000Z

Link: CVE-2024-44815

cve-icon Vulnrichment

Updated: 2024-09-10T20:21:15.169Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-10T16:15:20.453

Modified: 2024-09-25T19:17:02.237

Link: CVE-2024-44815

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses