WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.
2017-06-20T00:29:00.267
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | greenpacket | ox350_firmware | - | Yes |
Hardware | greenpacket | ox350 | - | No |
Operating System | huawei | bm2022_firmware | - | Yes |
Hardware | huawei | bm2022 | - | No |
Operating System | huawei | hes-309m_firmware | - | Yes |
Hardware | huawei | hes-309m | - | No |
Operating System | huawei | hes-319m_firmware | - | Yes |
Hardware | huawei | hes-319m | - | No |
Operating System | huawei | hes-319m2w_firmware | - | Yes |
Hardware | huawei | hes-319m2w | - | No |
Operating System | huawei | hes-339m_firmware | - | Yes |
Hardware | huawei | hes-339m | - | No |
Operating System | mada | soho_wireless_router_firmware | - | Yes |
Hardware | mada | soho_wireless_router | - | No |
Operating System | zte | ox-330p_firmware | - | Yes |
Hardware | zte | ox-330p | - | No |
Operating System | zyxel | max218m_firmware | - | Yes |
Hardware | zyxel | max218m | - | No |
Operating System | zyxel | max218m1w_firmware | - | Yes |
Hardware | zyxel | max218m1w | - | No |
Operating System | zyxel | max218mw_firmware | - | Yes |
Hardware | zyxel | max218mw | - | No |
Operating System | zyxel | max308m_fimware | - | Yes |
Hardware | zyxel | max308m | - | No |
Operating System | zyxel | max318m_firmware | - | Yes |
Hardware | zyxel | max318m | - | No |
Operating System | zyxel | max338m_firmware | - | Yes |
Hardware | zyxel | max338m | - | No |