← Back

Web6000q Firmware

web6000q_firmware

Vendor: Actiontec • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Actiontec
1Web6000q Firmware
Nov 21, 2024
Jun 28, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
On Telus Actiontec WEB6000Q v1.1.02.22 devices, an attacker can login with root level access with the user "root" and password "admin" by using the enabled onboard UART headers.
1Actiontec
1Web6000q Firmware
Nov 21, 2024
Jun 27, 2019
N/A· v4
8.8 HIGH· v3
10.0 HIGH· v2
An issue was discovered in the Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 devices. An attacker can statically set his/her IP to anything on the 169.254.1.0/24 subnet, and obtain root access by conne...Show more
An issue was discovered in the Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 devices. An attacker can statically set his/her IP to anything on the 169.254.1.0/24 subnet, and obtain root access by connecting to 169.254.1.2 port 23 with telnet/netcat.Show less
1Actiontec
1Web6000q Firmware
Nov 21, 2024
Jun 27, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "root" and an empty password by using the enabled onboard UART headers.