CVE-2017-14243

CRITICAL

UTStar WA3002G4 ADSL Broadband Modem - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-14243. PoCs published by Gem George.

AI-analyzed exploit summary The exploit describes an authentication bypass vulnerability in UTStar WA3002G4 ADSL modems, where accessing admin pages with a .cgi extension bypasses authentication. It also discloses plaintext passwords in the page source.

Description

An authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers to directly access administrative settings and obtain cleartext credentials from HTML source, as demonstrated by info.cgi, upload.cgi, backupsettings.cgi, pppoe.cgi, resetrouter.cgi, and password.cgi.

Exploits (1)

exploitdb WRITEUP
by Gem George · textwebappshardware
https://www.exploit-db.com/exploits/42739

The exploit describes an authentication bypass vulnerability in UTStar WA3002G4 ADSL modems, where accessing admin pages with a .cgi extension bypasses authentication. It also discloses plaintext passwords in the page source.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: UTStar WA3002G4 ADSL Broadband Modem (Firmware: WA3002G4-0021.01)
No auth needed
Prerequisites: Network access to the modem's web interface · Knowledge of the modem's IP address
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/42739/

Scores

CVSS v3 9.8
EPSS 0.1479
EPSS Percentile 96.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
utstar/wa3002g4_firmware wa3002g4-0021.01
Published Sep 17, 2017
Tracked Since Feb 18, 2026