vendor:
WA3002G4 ADSL Broadband Modem
by:
Gem George
9,8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: WA3002G4 ADSL Broadband Modem
Affected Version From: WA3002G4-0021.01
Affected Version To: WA3002G4-0021.01
Patch Exists: YES
Related CWE: CVE-2017-14243
CPE: h:utstar:wa3002g4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
UTStar WA3002G4 ADSL Broadband Modem Authentication Bypass Vulnerability
The CGI version of the admin page of UTStar modem does not authenticate the user and hence any protected page in the modem can be directly accessed by replacing page extension with cgi. This could also allow anyone to perform operations such as reset modem, change passwords, backup configuration without any authentication. The modem also disclose passwords of each users (Admin, Support and User) in plain text behind the page source.
Mitigation:
Ensure that authentication is enabled for all protected pages in the modem.