vendor:
MTS MBlaze 3G Wi-Fi Modem
by:
Ajin Abraham
9,8
CVSS
HIGH
Login Bypass | Router Credential Stealing | Wi-Fi Password Stealing | CSRF | Reset Password without old password and Session
N/A
CWE
Product Name: MTS MBlaze 3G Wi-Fi Modem
Affected Version From: 107
Affected Version To: 107
Patch Exists: YES
Related CWE: N/A
CPE: h:zte:ac3633
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
MTS MBlaze Ultra Wi-Fi / ZTE AC3633 Exploit
Ajin Abraham discovered multiple vulnerabilities in MTS MBlaze Ultra Wi-Fi / ZTE AC3633, including login bypass, router credential stealing, Wi-Fi password stealing, CSRF, and reset password without old password and session. An attacker can exploit these vulnerabilities to gain unauthorized access to the router.
Mitigation:
Users should update their router firmware to the latest version and use strong passwords for authentication.