Skip to main content

Vendor/product archive

starry / s00111 CVEs

Beta · best-effort

2 CVEs tagged to starry / s001110 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2017-13718

Published Jun 10, 2019

The HTTP API supported by Starry Station (aka Starry Router) allows brute forcing the PIN setup by the user on the device, and this allows an attacker to change the Wi-Fi settings…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2017-13717

Published Jun 10, 2019

Starry Station (aka Starry Router) sets the Access-Control-Allow-Origin header to "*". This allows any hosted file on any domain to make calls to the device's webserver and brute…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1