CVE-2003-1442 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.6% (pctl 85)
Patch early
A public exploit exists.
Description
The web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remote attackers to gain access from the LAN side.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.64% — more likely to be exploited than 85% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ericsson | hm220dp adsl modem |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Ericsson HM220dp DSL Modem - World Accessible Web Administration Interface | 2003-02-11 |
References
- http://archives.neohapsis.com/archives/bugtraq/2003-02/0127.html
- http://marc.info/?l=bugtraq&m=104619331706574&w=2
- http://www.securityfocus.com/bid/6824
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11290
- http://archives.neohapsis.com/archives/bugtraq/2003-02/0127.html
- http://marc.info/?l=bugtraq&m=104619331706574&w=2
- http://www.securityfocus.com/bid/6824
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11290
→ the Explorer · watch your stack · NVD