CVE-2018-13109
Estado: ModificadaAlta (7.5)—
All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able to access and manipulate settings within the web interface that are forbidden to end users (e.g., by the ISP). An attacker would be able to enable the TELNET server or other settings as well.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 35%
- Percentil entre todas las CVEs puntuadas: 98
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- CWE-863
Referencias
- http://packetstormsecurity.com/files/148429/ADB-Authorization-Bypass.html
- http://seclists.org/fulldisclosure/2018/Jul/18
- http://www.securityfocus.com/archive/1/542119/100/0/threaded
- https://www.exploit-db.com/exploits/44982/
- https://www.sec-consult.com/en/blog/advisories/authorization-bypass-in-all-adb-broadband-gateways-routers/
- http://packetstormsecurity.com/files/148429/ADB-Authorization-Bypass.html
- http://seclists.org/fulldisclosure/2018/Jul/18
- http://www.securityfocus.com/archive/1/542119/100/0/threaded
- https://www.exploit-db.com/exploits/44982/
- https://www.sec-consult.com/en/blog/advisories/authorization-bypass-in-all-adb-broadband-gateways-routers/
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-13109",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": true,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2018-07-06T14:29:01.100",
"references": [
{
"url": "http://packetstormsecurity.com/files/148429/ADB-Authorization-Bypass.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2018/Jul/18",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/542119/100/0/threaded",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/44982/",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.sec-consult.com/en/blog/advisories/authorization-bypass-in-all-adb-broadband-gateways-routers/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.com/files/148429/ADB-Authorization-Bypass.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2018/Jul/18",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/542119/100/0/threaded",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/44982/",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.sec-consult.com/en/blog/advisories/authorization-bypass-in-all-adb-broadband-gateways-routers/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able to access and manipulate settings within the web interface that are forbidden to end users (e.g., by the ISP). An attacker would be able to enable the TELNET server or other settings as well."
},
{
"lang": "es",
"value": "Todos los gateways/routers ADB basados en la plataforma Epicentro se han visto afectados por una vulnerabilidad de omisión de autorización por la que los atacantes pueden acceder y manipular opciones en la interfaz web que le están prohibidas a los usuarios finales (p. ej., por el ISP). Un atacante podría ser capaz de habilitar el servidor TELNET u otras opciones."
}
],
"lastModified": "2026-06-17T01:38:52.017",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:adbglobal:dv2210_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A77BB710-A438-4103-9414-053669AE1E5A"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:adbglobal:dv2210:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4C413482-3B9F-43B6-BBEF-6798950BD3F0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:adbglobal:vv2220_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "81AE15CE-5C84-42C1-86AD-3DE25D87671C"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:adbglobal:vv2220:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "EB5F965B-9757-4AEF-B056-F3EC9CBED5AD"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:adbglobal:vv5522_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A2E590FB-1395-4A3F-AFE5-9BA7FB06D791"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:adbglobal:vv5522:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "359E299D-7BD3-4D4C-B9E6-D3922F96EF0E"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:adbglobal:prg_av4202n_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F838B4CD-0B34-45B7-A074-AEF007415D1D"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:adbglobal:prg_av4202n:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "57088CE6-970A-477F-93B4-A39498685358"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}