10

CVE-2017-3216

Exploit

WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.

Data is provided by the National Vulnerability Database (NVD)
GreenpacketOx350 Firmware Version-
   GreenpacketOx350 Version-
HuaweiBm2022 Firmware Version-
   HuaweiBm2022 Version-
HuaweiHes-309m Firmware Version-
   HuaweiHes-309m Version-
HuaweiHes-319m Firmware Version-
   HuaweiHes-319m Version-
HuaweiHes-319m2w Firmware Version-
   HuaweiHes-319m2w Version-
HuaweiHes-339m Firmware Version-
   HuaweiHes-339m Version-
ZteOx-330p Firmware Version-
   ZteOx-330p Version-
ZyxelMax218m Firmware Version-
   ZyxelMax218m Version-
ZyxelMax218m1w Firmware Version-
   ZyxelMax218m1w Version-
ZyxelMax218mw Firmware Version-
   ZyxelMax218mw Version-
ZyxelMax308m Fimware Version-
   ZyxelMax308m Version-
ZyxelMax318m Firmware Version-
   ZyxelMax318m Version-
ZyxelMax338m Firmware Version-
   ZyxelMax338m Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.17% 0.862
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.