vendor:
Zoom X4 ADSL Modem and Router, Zoom X5 ADSL Modem and Router, Zoom X3 ADSL Modem
by:
Anonymous
8,8
CVSS
HIGH
Bypassing Authorization and Credential Challenges
287
CWE
Product Name: Zoom X4 ADSL Modem and Router, Zoom X5 ADSL Modem and Router, Zoom X3 ADSL Modem
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Vulnerable Products
When UPnP services and WAN http administrative access are enabled, authorization and credential challenges can be bypassed by directly accessing root privileged abilities via a web browser URL. All aspects of the modem/router can be changed, altered and controlled by an attacker, including gaining access to and changing the PPPoe/PPP ISP credentials.
Mitigation:
At this time, there are no known patches or fixes.