20050219 Thomson TCW690 POST Password Validation Vulnerabilitymailing list
http://marc.info/?l=bugtraq&m=110886937131507&w=2 CVE-2005-0494
Thomson TCW690 - POST Password Validation
Record summary
CVE-2005-0494 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct POST request.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBThomson TCW690 - POST Password ValidationExploitDB exploitby MurDoKNot analyzed1 file
References
414353Third-party advisory
http://secunia.com/advisories/14353 thomson-tcw690-gain-access(19387)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/19387 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-0494