header-logo
Suggest Exploit
vendor:
TWG850-4 Wireless VoIP Cable Modem
by:
Glafkos Charalambous, George Nicolaou
9,3
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: TWG850-4 Wireless VoIP Cable Modem
Affected Version From: ST9A.01.06
Affected Version To: ST9A.01.06
Patch Exists: NO
Related CWE: N/A
CPE: h:thomson:twg850-4_wireless_voip_cable_modem
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: None
2011

Thomson Wireless VoIP Cable Modem Auth Bypass

This exploit allows an attacker to bypass authentication on Thomson Wireless VoIP Cable Modem. The exploit uses the http_post() function to send a POST request to the modem with the parameters cbDomainBlocking, BasicParentalNewKeyword, BasicParentalKeywordAction, BasicParentalDomainList, BasicParentalNewDomain, BasicParentalDomainAction, cbKeywordBlocking, BasicParentalNewKeyword, BasicParentalKeywordAction, BasicParentalNewDomain, BasicParentralDomainAction, HttpUserId, Password, PasswordReEnter, RestoreFactoryYes. This allows the attacker to reset the password, block domains and keywords, and restore factory defaults.

Mitigation:

Ensure that authentication is properly implemented and enforced on the device.
Source

Exploit-DB raw data: