PT-2017-15284 · Toshiba · Toshiba Home Gateway Hem-Gw16A+1

Yutaka Kokubu

·

Published

2017-07-07

·

Updated

2020-08-24

·

CVE-2017-2235

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Toshiba Home gateway HEM-GW16A versions HEM-GW16A-FW-V1.2.0 and earlier Toshiba Home gateway HEM-GW26A versions HEM-GW26A-FW-V1.2.0 and earlier
Description The issue allows an attacker to bypass access restrictions and change the administrator account password. This is achieved via unspecified vectors, potentially allowing unauthorized access to the system.
Recommendations For Toshiba Home gateway HEM-GW16A versions HEM-GW16A-FW-V1.2.0 and earlier, update to a version later than HEM-GW16A-FW-V1.2.0 to resolve the issue. For Toshiba Home gateway HEM-GW26A versions HEM-GW26A-FW-V1.2.0 and earlier, update to a version later than HEM-GW26A-FW-V1.2.0 to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-2235

Affected Products

Toshiba Home Gateway Hem-Gw16A
Toshiba Home Gateway Hem-Gw26A