PT-2006-1990 · Thomson · Thomson Speedtouch
Publicado
2006-03-01
·
Atualizado
2011-03-08
·
CVE-2006-0947
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Thomson SpeedTouch modem version 5.3.2.6.0
Description
The issue allows remote attackers to create users that cannot be deleted via scripting code in the
31 parameter in a NewUser function. This function is not filtered by the modem when creating the account, but the created users cannot be deleted by the administrator, possibly due to cleansing that occurs in the administrator interface.Recommendations
For Thomson SpeedTouch modem version 5.3.2.6.0, as a temporary workaround, consider restricting the use of the
NewUser function until a patch is available. Additionally, avoid using the 31 parameter in the affected function to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Thomson Speedtouch