Vulnerability Details CVE-2017-14243
An authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers to directly access administrative settings and obtain cleartext credentials from HTML source, as demonstrated by info.cgi, upload.cgi, backupsettings.cgi, pppoe.cgi, resetrouter.cgi, and password.cgi.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.603
EPSS Ranking 98.2%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2017-14243
-
cpe:2.3:h:utstar:wa3002g4:-
-
cpe:2.3:o:utstar:wa3002g4_firmware:wa3002g4-0021.01