CVE-2017-14243
CRITICALUTStar WA3002G4 ADSL Broadband Modem - Auth Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-14243. PoCs published by Gem George.
AI-analyzed exploit summary The exploit describes an authentication bypass vulnerability in UTStar WA3002G4 ADSL modems, where accessing admin pages with a .cgi extension bypasses authentication. It also discloses plaintext passwords in the page source.
Description
An authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers to directly access administrative settings and obtain cleartext credentials from HTML source, as demonstrated by info.cgi, upload.cgi, backupsettings.cgi, pppoe.cgi, resetrouter.cgi, and password.cgi.
Exploits (1)
The exploit describes an authentication bypass vulnerability in UTStar WA3002G4 ADSL modems, where accessing admin pages with a .cgi extension bypasses authentication. It also discloses plaintext passwords in the page source.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H