Back

MEDIUM

Password Storage in Plaintext Vulnerability in Digisol Router

Published May 10, 2024

Description

This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to lack of encryption or hashing in storing of passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext passwords on the vulnerable system.

Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted system.

Affected products

Remediation

Vendor solution

Upgrade Digisol Router firmware to version v3.1.02-240311. https://www.digisol.com/firmware/

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERT-In
Published May 10, 2024
Updated Aug 1, 2024
Reserved Apr 26, 2024
CISA Vulnrichment
Updated May 14, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a