Record summary

CVE-2005-0494 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.

Description

The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct POST request.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBThomson TCW690 - POST Password ValidationExploitDB exploitby MurDoKNot analyzed1 file
ExploitDB

PoC details

References

4