CVE-2017-9488

HIGH

Comcast Cisco DPC3939-3941T - RCE

Title source: llm
STIX 2.1

Description

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) and DPC3941T (firmware version DPC3941_2.5s3_PROD_sey) devices allows remote attackers to access the web UI by establishing a session to the wan0 WAN IPv6 address and then entering unspecified hardcoded credentials. This wan0 interface cannot be accessed from the public Internet.

Scores

CVSS v3 8.8
EPSS 0.0030
EPSS Percentile 52.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (2)
cisco/dpc3939_firmware dpc3939-p20-18-v303r20421746-170221a-cmcst
cisco/dpc3941t_firmware dpc3941_2.5s3_prod_sey
Published Jul 31, 2017
Tracked Since Feb 18, 2026