WiFiRanger devices with firmware version 7.0.8rc3 and earlier contain an incorrect access control vulnerability in their FTP configuration. This flaw allows an attacker with access to the adjacent network to read sensitive files, including the SSH private key, which can then be used to gain root access to the device.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a simple Bash exploit script (wifiRangerPwn.sh) targeting WiFiRanger routers (Core, GoAC, Sky Pro, EliteAC, EliteAC FM) running firmware version 7.0.8rc3 and earlier, as described in CVE-2018-17873. The exploit leverages two misconfigurations: anonymous FTP access and the presence of the root SSH private key in a world-readable location on the device. The script takes the target device's IP address as an argument, downloads the root SSH private key via FTP, sets the correct permissions, and then uses it to log in as root via SSH. The repository is minimal, containing only a license, a README with usage instructions, and the exploit script. The main attack vector is network-based, requiring adjacent network access to the vulnerable device. The endpoints involved are the FTP path to the SSH key and the SSH service for root login.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.