vendor:
CT-5367 C01_R12
by:
Todor Donev
7.5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: CT-5367 C01_R12
Affected Version From: A111-312BTC-C01_R12
Affected Version To: A111-312BTC-C01_R12
Patch Exists: NO
Related CWE: N/A
CPE: h:comtrend:ct-5367_c01_r12
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2000
COMTREND ADSL Router BTC(VivaCom) CT-5367 C01_R12 Remote Root
A vulnerability in the COMTREND ADSL Router BTC(VivaCom) CT-5367 C01_R12 allows an unauthenticated attacker to gain access to the router's passwords. By sending a GET request to the router's password.cgi page, the attacker can view the router's passwords in plaintext.
Mitigation:
Ensure that the router is running the latest version of firmware and that all passwords are changed to strong, unique passwords.