In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for any unconfigured release of OpenWRT, and true of many other new Linux distros prior to being configured for the first time”
Metrics
Affected Vendors & Products
References
History
Mon, 23 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published: 2020-04-21T12:08:11.000Z
Updated: 2024-08-04T11:48:56.413Z
Reserved: 2020-04-20T00:00:00.000Z
Link: CVE-2020-11967
Updated: 2024-08-04T11:48:56.413Z
Status : Modified
Published: 2020-04-21T13:15:15.067
Modified: 2024-11-21T04:59:00.543
Link: CVE-2020-11967
No data.