vendor:
DWG849 Cable Modem Gateway
by:
Matt Dunlap
N/A
CVSS
N/A
Information Exposure
200
CWE
Product Name: DWG849 Cable Modem Gateway
Affected Version From: Thomson CableHome Gateway <<MODEL: DWG849>> Cable Modem Gateway
Affected Version To: Thomson CableHome Gateway <<MODEL: DWG849>> Cable Modem Gateway
Patch Exists: NO
Related CWE: Not reported to vendor (yet)
CPE: h:thomson:dwg849_cable_modem_gateway
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 14.04.3
2015
Information Exposure via SNMP on Thomson CableHome Gateway
A vulnerability exists in Thomson CableHome Gateway DWG849 Cable Modem Gateway product specifications which allows local/remote network users to discover user interface credentials and wireless network key values through simple SNMP requests for the value of these variables. Given the security authentication in SNMPv1 and SNMPv2c do not offer sufficient protection, this increases the risk that the values can be disclosed through SNMP using the default read-only community “private”.
Mitigation:
The vendor has not released a patch for this vulnerability.