CVE Database
/

CVE-2017-3216

Back to search

CVE-2017-3216

Published: Jun 20, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.

VendorProductVersions

Huawei Technologies

BM2022

affected
2.10.14

Huawei Technologies

HES-309M

affected
unknown

Huawei Technologies

HES-319M

affected
unknown

Huawei Technologies

HES-319M2W

affected
unknown

Huawei Technologies

HES-339M

affected
unknown

Green Packet

OX350

affected
unknown

ZTE

OX-330P

affected
unknown

ZyXEL

MAX218M

affected
2.00(UXG.0)D0

ZyXEL

MAX218M1W

affected
2.00(UXE.3)D0

ZyXEL

MAX218MW

affected
2.00(UXD.2)D0

ZyXEL

MAX308M

affected
2.00(UUA.3)D0

ZyXEL

MAX318M

affected
unknown

ZyXEL

MAX338M

affected
unknown

MADA

Soho Wireless Router

affected
2.10.13

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now