PT-2017-13319 · Utstar · Utstar Wa3002G4 Adsl Broadband Modem

Gem George

·

Published

2017-09-17

·

Updated

2019-10-03

·

CVE-2017-14243

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UTStar WA3002G4 ADSL Broadband Modem version WA3002G4-0021.01
Description The issue allows attackers to bypass authentication and directly access administrative settings. Attackers can obtain cleartext credentials from the HTML source of various CGI files, including "info.cgi", "upload.cgi", "backupsettings.cgi", "pppoe.cgi", "resetrouter.cgi", and "password.cgi".
Recommendations For UTStar WA3002G4 ADSL Broadband Modem version WA3002G4-0021.01, consider restricting access to the mentioned CGI files, such as "info.cgi", "upload.cgi", "backupsettings.cgi", "pppoe.cgi", "resetrouter.cgi", and "password.cgi", until a patch is available.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14243

Affected Products

Utstar Wa3002G4 Adsl Broadband Modem