CVE-2016-7454

HIGH

Technicolor Xfinity Gateway Router Dpc3941t Firmware - CSRF

Title source: rule

Description

CSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r20421733-160413a-CMCST allows an attacker to change the Wi-Fi password, open the remote management interface, or reset the router.

Exploits (1)

exploitdb WORKING POC
by Ayushman Dutta · htmlwebappshardware
https://www.exploit-db.com/exploits/40982

Scores

CVSS v3 8.0
EPSS 0.0104
EPSS Percentile 77.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
technicolor/xfinity_gateway_router_dpc3941t_firmware dpc3941-p20-18-v303r20421733-160413a-cmcst
Published Dec 17, 2016
Tracked Since Feb 18, 2026