CP Plus CP-VNR-3104
cpe:2.3:h:cpplusworld:cp-vnr-3104:*:*:*:*:*:*:*, +1 more
A vulnerability in the CP Plus CP-VNR-3104 model allows attackers to access the Diffie-Hellman (DH) parameters, potentially leading to the exposure of sensitive data or the execution of a man-in-the-middle attack. This issue arises from the device's handling of DH parameters, which can be exploited to intercept or manipulate communications.
Exploitation of this vulnerability could allow for unauthorized access to sensitive data or the interception and alteration of communications, facilitating a man-in-the-middle attack.
The vulnerability can be reproduced by accessing the device's firmware update mechanism, which is available on the manufacturer's FTP server. After uploading a crafted firmware file, the device will decrypt and install the update, during which the DH parameters can be intercepted.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.