Back

CVE-2017-14244

CRITICAL

An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access administrative router settings by crafting URLs with a .cgi extension, as demonstrated by /info.cgi and /password.cgi.

Published: Sep 17, 2017 Modified: Jun 17, 2026
CWE-425

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
iball ib-wra150n_firmware fw_ib-lr7011a_1.0.2

GitHub Security Advisory GHSA-8hp6-w36x-5x7g

An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 17.15%

Top 3% most likely to be exploited

Threat Score 44.3 / 100

Data Sources

NVD EPSS GitHub