PT-2016-7340 · Technicolor · Tc Dpc3941T
Published
2016-12-17
·
Updated
2016-12-21
·
CVE-2016-7454
CVSS v3.1
8.0
High
| Vector | AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r20421733-160413a-CMCST
Description
The issue allows an attacker to perform unauthorized actions such as changing the Wi-Fi password, opening the remote management interface, or resetting the router due to a CSRF vulnerability.
Recommendations
For Technicolor TC dpc3941T devices with firmware dpc3941-P20-18-v303r20421733-160413a-CMCST, consider disabling remote management as a temporary workaround until a patch is available. Restrict access to the device's management interface to minimize the risk of exploitation. Avoid using the device until the issue is resolved or a fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tc Dpc3941T