PT-2017-13319 · Utstar · Utstar Wa3002G4 Adsl Broadband Modem
Gem George
·
Published
2017-09-17
·
Updated
2019-10-03
·
CVE-2017-14243
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UTStar WA3002G4 ADSL Broadband Modem version WA3002G4-0021.01
Description
The issue allows attackers to bypass authentication and directly access administrative settings. Attackers can obtain cleartext credentials from the HTML source of various CGI files, including "info.cgi", "upload.cgi", "backupsettings.cgi", "pppoe.cgi", "resetrouter.cgi", and "password.cgi".
Recommendations
For UTStar WA3002G4 ADSL Broadband Modem version WA3002G4-0021.01, consider restricting access to the mentioned CGI files, such as "info.cgi", "upload.cgi", "backupsettings.cgi", "pppoe.cgi", "resetrouter.cgi", and "password.cgi", until a patch is available.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Utstar Wa3002G4 Adsl Broadband Modem