Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-24848 – FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPA

FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform a system-level (root) local privilege escalation, allowing an attacker to gain complete persistent access to the local system.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24848

Reference (s):

  • https://gist.github.com/harsh-bothra/5be73cfd53f1c5bea307c702ae83ff42
  • https://github.com/xtr4nge/FruityWifi/issues/278
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-5980 - The Genertel (aka com.genertel) application 2.6.0 for Android does not ve

2021-current

CVE-2019-7853 - A stored cross-site scripting vulnerability exists in Magento 2.1 prior t

2021-current

CVE-2020-1161 - A denial of service vulnerability exists when ASP.NET Core improperly han