CVE-2011-0887

SMC SMCD3G-CCR - Session Hijacking via Predictable Session ID

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-0887. PoCs published by Trustwave's SpiderLabs.

AI-analyzed exploit summary The exploit demonstrates a CSRF vulnerability in Comcast DOCSIS 3.0 Business Gateways (D3G-CCR) by embedding malicious requests in HTML forms to enable remote administration and modify DNS settings. It includes functional PoC code that automates login and configuration changes via hidden form submissions.

Description

The web management portal on the SMC SMCD3G-CCR (aka Comcast Business Gateway) with firmware before 1.4.0.49.2 uses predictable session IDs based on time values, which makes it easier for remote attackers to hijack sessions via a brute-force attack on the userid cookie.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Trustwave's SpiderLabs · textremotehardware
https://www.exploit-db.com/exploits/16123

The exploit demonstrates a CSRF vulnerability in Comcast DOCSIS 3.0 Business Gateways (D3G-CCR) by embedding malicious requests in HTML forms to enable remote administration and modify DNS settings. It includes functional PoC code that automates login and configuration changes via hidden form submissions.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Comcast DOCSIS 3.0 Business Gateway - D3G-CCR (versions prior to 1.4.0.49.2)
No auth needed
Prerequisites: Victim must be logged into the gateway's management interface · Attacker must lure victim to a malicious webpage
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit mailing-list x_refsource_bugtraq
http://seclists.org/bugtraq/2011/Feb/36
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/65186
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43199
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8068
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/46215
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/16123/
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/516205/100/0/threaded

Scores

EPSS 0.0467
EPSS Percentile 90.6%

Details

CWE
CWE-310
Status published
Products (2)
smc_networks/smcd3g-ccr
smc_networks/smcd3g-ccr_firmware 1.4.0.42
Published Feb 08, 2011
Tracked Since Feb 18, 2026