PT-2007-6435 · Bt+1 · Bt Home Hub+2

Adrian Pastor

+1

·

Published

2007-10-12

·

Updated

2018-10-15

·

CVE-2007-5384

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Thomson/Alcatel SpeedTouch 7G router versions 6.2.6.B and earlier BT Home Hub version 6.2.6.B and earlier SpeedTouch 780 (affected versions not specified)
Description: The issue allows remote attackers to perform actions as administrators via unspecified POST requests. This can be demonstrated by enabling an inbound remote-assistance HTTPS session on TCP port 51003. An authentication bypass can be leveraged to exploit this issue in the absence of an existing administrative session.
Recommendations: For Thomson/Alcatel SpeedTouch 7G router versions 6.2.6.B and earlier, consider restricting access to administrative functions until a fix is available. For BT Home Hub version 6.2.6.B and earlier, restrict inbound remote-assistance HTTPS sessions on TCP port 51003 to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5384

Affected Products

Bt Home Hub
Speedtouch 780
Speedtouch 7G