CVE-2013-5038 describes an authentication bypass vulnerability in the HOT HOTBOX router running software version 2.1.11. This flaw allows remote attackers to gain unauthorized access by spoofing a source IP address previously used by an authenticated user. The vulnerability has a CVSS score of 5.8, indicating a medium severity, with an adjacent network attack vector, low complexity, and potential for partial compromise of confidentiality, integrity, and availability. While there is an ExploitDB entry (EDB-29518) referencing multiple vulnerabilities in a similar device, there is no indication of active exploitation, Metasploit or Nuclei modules, or significant community discussion for this specific CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1.11CPE matchmatch criteria | cpe:2.3:o:hot:hotbox_router_firmware:2.1.11:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:hot:hotbox_router:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:A/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.