CVE-2017-3216

CRITICAL

Greenpacket Ox350 Firmware - Missing Authentication

Title source: rule
STIX 2.1

Description

WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.

References (3)

Core 3
Core References
Mitigation, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/350135

Scores

CVSS v3 9.8
EPSS 0.0317
EPSS Percentile 87.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-306
Status published
Products (28)
Green Packet/OX350
greenpacket/ox350_firmware
huawei/bm2022_firmware
huawei/hes-309m_firmware
huawei/hes-319m2w_firmware
huawei/hes-319m_firmware
huawei/hes-339m_firmware
Huawei Technologies/BM2022 2.10.14
Huawei Technologies/HES-309M
Huawei Technologies/HES-319M
... and 18 more
Published Jun 20, 2017
Tracked Since Feb 18, 2026