vendor:
ADSL Modem/Router line
by:
N/A
N/A
CVSS
N/A
Directory Traversal/Unauthenticated access to administrative panels and Improper handling of unexpected characters/data
22, 20
CWE
Product Name: ADSL Modem/Router line
Affected Version From: 1.0.X
Affected Version To: 3.2
Patch Exists: NO
Related CWE: CVE-2013-5622, CVE-2013-5627, CVE-2013-5624, CVE-2013-5623, CVE-2013-5628, CVE-2013-5625
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
Multiple Critical Vulnerabilities in Zoom Telephonics ADSL Modem/Router Line
By simply placing the following two URLs into a web browser, a vulnerability will all models and firmware versions allow for bypass of administrative credential challenge. All models and firmware versions can access these pages with no authentication. An un-authenticated user can preform almost all administrative tasks once the authentication is bypassed. By sending a specially crafted packet to the modem, an attacker can cause the modem to crash and reboot. This can be done remotely and repeatedly, causing a denial of service.
Mitigation:
N/A