You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
id: 2573title: 'RVD#2573: The DBPOWER U818A WIFI quadcopter drone provides FTP access over 'type: vulnerabilitydescription: The DBPOWER U818A WIFI quadcopter drone provides FTP access over itsown local access point, and allows full file permissions to the anonymous user.The DBPower U818A WIFI quadcopter drone runs an FTP server that by default allowsanonymous access without a password, and provides full filesystem read/write permissionsto the anonymous user. A remote user within range of the open access point on thedrone may utilize the anonymous user of the FTP server to read arbitrary files,such as images and video recorded by the device, or to replace system files suchas /etc/shadow to gain further access to the device. Furthermore, the DBPOWER U818AWIFI quadcopter drone uses BusyBox 1.20.2, which was released in 2012, and may bevulnerable to other known BusyBox vulnerabilities.cwe: CWE-276cve: CVE-2017-3209keywords: ''system: 'DBPOWER U818A'vendor: "DBPOWER"severity:
rvss-score: 0rvss-vector: ''severity-description: 'medium'cvss-score: 4.8cvss-vector: CVSS:3.0/AV:A/AC:L/Au:N/C:P/I:P/A:Nlinks:
- https://dl.acm.org/doi/10.1145/3139937.3139943
- https://vulners.com/cve/CVE-2017-3209
- https://github.com/aliasrobotics/RVD/issues/2573
- https://nvd.nist.gov/vuln/detail/CVE-2017-3209flaw:
phase: unknownspecificity: N/Aarchitectural-location: N/Aapplication: N/Asubsystem: N/Apackage: N/Alanguages: Nonedate-detected: '2018-07-24'detected-by: ''detected-by-method: N/Adate-reported: '2020-05-29'reported-by: ''reported-by-relationship: N/Aissue: https://github.com/aliasrobotics/RVD/issues/2573reproducibility: ''trace: ''reproduction: ''reproduction-image: ''exploitation:
description: ''exploitation-image: ''exploitation-vector: ''exploitation-recipe: ''mitigation:
description: ''pull-request: ''date-mitigation: ''
The text was updated successfully, but these errors were encountered:
rvd-bot
changed the title
The DBPOWER U818A WIFI quadcopter drone provides FTP access over
RVD#2573: The DBPOWER U818A WIFI quadcopter drone provides FTP access over
Jun 28, 2020
The text was updated successfully, but these errors were encountered: