vendor:
F@ST 3864 V2
by:
Cade Bull
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: F@ST 3864 V2
Affected Version From: 7.253.2_F3864V2_Optus
Affected Version To: 7.253.2_F3864V2_Optus
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
Sagemcom 3864 V2 get admin password
The Sagemcom modem does not authenticate users when requesting pages, only whilst posting forms. The password.html page loads the admin password in clear text and stores it in Javascript, which is viewable without any credentials.
Mitigation:
Ensure that authentication is required for all pages and that passwords are not stored in plain text.