PT-2017-13319 · Utstar · Utstar Wa3002G4 Adsl Broadband Modem
Gem George
·
Publicado
2017-09-17
·
Atualizado
2019-10-03
·
CVE-2017-14243
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UTStar WA3002G4 ADSL Broadband Modem version WA3002G4-0021.01
Description
The issue allows attackers to bypass authentication and directly access administrative settings. Attackers can obtain cleartext credentials from the HTML source of various CGI files, including "info.cgi", "upload.cgi", "backupsettings.cgi", "pppoe.cgi", "resetrouter.cgi", and "password.cgi".
Recommendations
For UTStar WA3002G4 ADSL Broadband Modem version WA3002G4-0021.01, consider restricting access to the mentioned CGI files, such as "info.cgi", "upload.cgi", "backupsettings.cgi", "pppoe.cgi", "resetrouter.cgi", and "password.cgi", until a patch is available.
Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Utstar Wa3002G4 Adsl Broadband Modem