packetstormsecurity.com
http://packetstormsecurity.com/files/145121/ZTE-ZXDSL-831-Unauthorized-Configuration-Access-Bypass.html CVE-2017-16953
HIGH
ZTE ZXDSL 831CII - Improper Access Restrictions
Record summary
CVE-2017-16953 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration or set up a malicious configuration via a GET request.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBZTE ZXDSL 831CII - Improper Access RestrictionsExploitDB exploitby Ibad ShahNot analyzed1 file
References
4support.zte.com.cnConfirmation
http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008762 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-16953 43188exploit
https://www.exploit-db.com/exploits/43188