PT-2017-17132 · Televes · Coaxdata Gateway
Pandujar
+1
·
Published
2017-07-20
·
Updated
2019-10-03
·
CVE-2017-6530
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Televes COAXDATA GATEWAY 1Gbps devices version doc-wifi-hgw v1.02.0014 4.20
Description
The issue concerns the lack of password.shtml authorization checks, allowing for arbitrary password changes.
Recommendations
For version doc-wifi-hgw v1.02.0014 4.20, consider restricting access to the password change functionality until a fix is available. As a temporary workaround, avoid using the password change feature to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coaxdata Gateway