CVE-2017-3216
9.8
CRITICAL · CVSS 3.0 · EPSS 5.2% (pctl 92)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 5.18% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-306 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-06-20 |
| Last modified | 2026-06-17 |
Affected (28)
| Vendor | Product |
|---|---|
| greenpacket | ox350 |
| greenpacket | ox350 firmware |
| huawei | bm2022 |
| huawei | bm2022 firmware |
| huawei | hes-309m |
| huawei | hes-309m firmware |
| huawei | hes-319m |
| huawei | hes-319m firmware |
| huawei | hes-319m2w |
| huawei | hes-319m2w firmware |
| huawei | hes-339m |
| huawei | hes-339m firmware |
| mada | soho wireless router |
| mada | soho wireless router firmware |
| zte | ox-330p |
| zte | ox-330p firmware |
| zyxel | max218m |
| zyxel | max218m firmware |
| zyxel | max218m1w |
| zyxel | max218m1w firmware |
| zyxel | max218mw |
| zyxel | max218mw firmware |
| zyxel | max308m |
| zyxel | max308m fimware |
| zyxel | max318m |
| zyxel | max318m firmware |
| zyxel | max338m |
| zyxel | max338m firmware |
References
- http://blog.sec-consult.com/2017/06/ghosts-from-past-authentication-bypass.html
- http://www.kb.cert.org/vuls/id/350135
- https://sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170607-0_Various_WiMAX_CPEs_Authentication_Bypass_v10.txt
- http://blog.sec-consult.com/2017/06/ghosts-from-past-authentication-bypass.html
- http://www.kb.cert.org/vuls/id/350135
- https://sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170607-0_Various_WiMAX_CPEs_Authentication_Bypass_v10.txt
→ the Explorer · watch your stack · NVD