CVE-2017-13718
Published Jun 10, 2019The HTTP API supported by Starry Station (aka Starry Router) allows brute forcing the PIN setup by the user on the device, and this allows an attacker to change the Wi-Fi settings…
Vendor archive
2 CVEs tagged to vendor starry — 0 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.
The HTTP API supported by Starry Station (aka Starry Router) allows brute forcing the PIN setup by the user on the device, and this allows an attacker to change the Wi-Fi settings…
Starry Station (aka Starry Router) sets the Access-Control-Allow-Origin header to "*". This allows any hosted file on any domain to make calls to the device's webserver and brute…