VYPR

WEB6000Q

by Actiontec

CVEs (3)

  • CVE-2018-15555Jun 28, 2019
    risk 0.00cvss epss 0.03

    On Telus Actiontec WEB6000Q v1.1.02.22 devices, an attacker can login with root level access with the user "root" and password "admin" by using the enabled onboard UART headers.

  • CVE-2018-15556Jun 27, 2019
    risk 0.00cvss epss 0.03

    The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "root" and an empty password by using the enabled onboard UART headers.

  • CVE-2018-15557Jun 27, 2019
    risk 0.00cvss epss 0.03

    An issue was discovered in the Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 devices. An attacker can statically set his/her IP to anything on the 169.254.1.0/24 subnet, and obtain root access by connecting to 169.254.1.2 port 23 with telnet/netcat.