10

CVE-2017-3216

Exploit
WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Greenpacket ≫ Ox350 Firmware Version -
   Greenpacket ≫ Ox350 Version -
Huawei ≫ Bm2022 Firmware Version -
   Huawei ≫ Bm2022 Version -
Huawei ≫ Hes-309m Firmware Version -
   Huawei ≫ Hes-309m Version -
Huawei ≫ Hes-319m Firmware Version -
   Huawei ≫ Hes-319m Version -
Huawei ≫ Hes-319m2w Firmware Version -
   Huawei ≫ Hes-319m2w Version -
Huawei ≫ Hes-339m Firmware Version -
   Huawei ≫ Hes-339m Version -
Mada ≫ Soho Wireless Router Firmware Version -
   Mada ≫ Soho Wireless Router Version -
Zte ≫ Ox-330p Firmware Version -
   Zte ≫ Ox-330p Version -
Zyxel ≫ Max218m Firmware Version -
   Zyxel ≫ Max218m Version -
Zyxel ≫ Max218m1w Firmware Version -
   Zyxel ≫ Max218m1w Version -
Zyxel ≫ Max218mw Firmware Version -
   Zyxel ≫ Max218mw Version -
Zyxel ≫ Max308m Fimware Version -
   Zyxel ≫ Max308m Version -
Zyxel ≫ Max318m Firmware Version -
   Zyxel ≫ Max318m Version -
Zyxel ≫ Max338m Firmware Version -
   Zyxel ≫ Max338m Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.18% 0.914
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

http://blog.sec-consult.com/2017/06/ghosts-from-past-authentication-bypass.html
Third Party Advisory
http://www.kb.cert.org/vuls/id/350135
Third Party Advisory
US Government Resource
Mitigation
https://sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170607-0_Various_WiMAX_CPEs_Authentication_Bypass_v10.txt
Third Party Advisory
Exploit