Back

CVE-2017-11435

CRITICAL

The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management console. The bug is exploitable remotely when the router is configured to expose the management console. The router is not validating the session token while returning answers for some methods in url '/api'. An attacker can use this vulnerability to retrieve sensitive information such as private/public IP addresses, SSID names, and passwords.

Published: Jul 19, 2017 Modified: Jun 17, 2026
CWE-200

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
humaxdigital hg100r_firmware 2.0.6

GitHub Security Advisory GHSA-rx9w-4m5f-5vhf

The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 10.05%

Top 5% most likely to be exploited

Threat Score 42.2 / 100

Data Sources

NVD EPSS GitHub