vendor:
ZXDSL 831CII
by:
Paulos Yibelo
8,8
CVSS
HIGH
Insecure Direct Object Reference
639
CWE
Product Name: ZXDSL 831CII
Affected Version From: -
Affected Version To: -
Patch Exists: YES
Related CWE: -
CPE: -
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2014
ZTE ZXDSL 831 Insecure Direct Object Reference
ZTE ZXDSL 831CII suffers from an insecure direct object reference vulnerability that allows for authentication bypass. The modem usually serves html files & protects them with HTTP Basic authentication. however, the cgi files, does not get this protection. so simply requesting any cgi file (without no authentication) would give a remote attacker full access to the modem and then can easily be used to root the modem and disrupt network activities.
Mitigation:
Upgrade to the latest version of the ZTE ZXDSL 831CII firmware.