- Description
- ReadyNet WRT300N-DD devices with firmware 1.0.26 use the same source port number for every DNS query, which makes it easier for remote attackers to spoof responses by selecting that number for the destination port.
- Source
- cret@cert.org
- NVD status
- Modified
CVSS 3.0
- Type
- Primary
- Base score
- 5.8
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
- nvd@nist.gov
- CWE-20
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:readynet_solutions:wrt300n-dd_firmware:1.0.26:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "05F916B9-0067-443F-AB4D-C64ECF93A754"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:readynet_solutions:wrt300n-dd:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "75299693-129C-4040-A88E-DC9D4642E178"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]