PT-2017-15284 · Toshiba · Toshiba Home Gateway Hem-Gw16A+1
Yutaka Kokubu
·
Published
2017-07-07
·
Updated
2020-08-24
·
CVE-2017-2235
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Toshiba Home gateway HEM-GW16A versions HEM-GW16A-FW-V1.2.0 and earlier
Toshiba Home gateway HEM-GW26A versions HEM-GW26A-FW-V1.2.0 and earlier
Description
The issue allows an attacker to bypass access restrictions and change the administrator account password. This is achieved via unspecified vectors, potentially allowing unauthorized access to the system.
Recommendations
For Toshiba Home gateway HEM-GW16A versions HEM-GW16A-FW-V1.2.0 and earlier, update to a version later than HEM-GW16A-FW-V1.2.0 to resolve the issue.
For Toshiba Home gateway HEM-GW26A versions HEM-GW26A-FW-V1.2.0 and earlier, update to a version later than HEM-GW26A-FW-V1.2.0 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Toshiba Home Gateway Hem-Gw16A
Toshiba Home Gateway Hem-Gw26A