Iball develops a narrow line of wireless networking devices, primarily its WRA series routers and related firmware, which despite modest product count achieve notable presence in the landscape. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, concentrating through web-interface weakness classes including cross-site request forgery, hard-coded credentials, cleartext credential storage, and cross-site scripting that are typical of embedded device management surfaces. Defenders should prioritize inventory and isolation of these router models and treat firmware updates as urgent; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iball over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14244CRITICAL An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access administrative router settings | Sep 17, 2017 | 9.8 | 50 | NO | YES |
CVE-2017-6558CRITICAL iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify ad | Mar 9, 2017 | 9.8 | 44 | NO | YES |
CVE-2018-6388HIGH iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping test arguments on the | Jan 29, 2018 | 8.8 | 39 | NO | YES |
CVE-2018-6387CRITICAL iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices have a hardcoded password of admin for the admin account, a hardcoded password of support for the support account, and a hard | Jan 29, 2018 | 9.8 | 29 | NO | NO |
CVE-2017-11169HIGH Privilege Escalation on iBall iB-WRA300N3GT iB-WRA300N3GT_1.1.1 devices allows remote authenticated users to obtain root privileges by leveraging a guest/user/normal account to sub | Nov 13, 2017 | 8.8 | 27 | NO | NO |
CVE-2020-15043MEDIUM iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP addresses. | Jun 29, 2020 | 6.5 | 22 | NO | NO |
CVE-2018-20008MEDIUM iBall Baton iB-WRB302N20122017 devices have improper access control over the UART interface, allowing physical attackers to discover Wi-Fi credentials (plain text) and the web-cons | May 28, 2019 | 6.8 | 22 | NO | NO |
CVE-2018-6355MEDIUM /goform/setLang on iBall 300M devices with "iB-WRB302N_1.0.1-Sep 8 2017" firmware has Unauthenticated Stored Cross Site Scripting via the lang parameter. | Jan 30, 2018 | 6.1 | 20 | NO | NO |
CVE-2020-29292MEDIUM iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or modifying the range for IP addresses. | Dec 30, 2021 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iball.
Media articles that mention a CVE ID that affects a product developed by Iball — matched by CVE ID, not by vendor name.