CVE-2007-4387

2wire 1701HG and 2071 Gateway Routers - Cross-Site Request Forgery in /xslt

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-4387. Includes Metasploit module auxiliary/admin/2wire/xslt_password_reset.

AI-analyzed exploit summary This Metasploit module exploits a CSRF vulnerability in 2Wire routers to reset the admin password without authentication. It interacts with the /xslt endpoint to gather device information and then submits a password reset request.

Description

Cross-site request forgery (CSRF) vulnerability in /xslt in 2wire 1701HG and 2071 Gateway routers, with 3.17.5 and 5.29.51 software, allows remote attackers to perform certain configuration changes as administrators.

Exploits (1)

metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/2wire/xslt_password_reset.rb

This Metasploit module exploits a CSRF vulnerability in 2Wire routers to reset the admin password without authentication. It interacts with the /xslt endpoint to gather device information and then submits a password reset request.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: 2Wire wireless routers (version 5.x)
No auth needed
Prerequisites: Network access to the target router · Router must be a 2Wire model with vulnerable firmware
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/36044
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3026
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/476595/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26496
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37667

Scores

EPSS 0.5752
EPSS Percentile 98.2%

Details

Status published
Products (4)
2wire/1701hg_router 3.17.5
2wire/1701hg_router 5.29.51
2wire/2071_router 3.17.5
2wire/2071_router 5.29.51
Published Aug 17, 2007
Tracked Since Feb 18, 2026