CVE-2017-3216: Critical severity greenpacket ox350 firmware vulnerability

Published Jun 20, 2017
·
Updated

WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.

Affected Software

28 affected components
GreenPacket Ox350 Firmware
GreenPacket Ox350
Huawei Bm2022 Firmware
Huawei Bm2022
Huawei Hes-309m Firmware
Huawei Hes-309m
Huawei Hes-319m Firmware
Huawei Hes-319m
Huawei Hes-319m2w Firmware
Huawei Hes-319m2w
Huawei Hes-339m Firmware
Huawei Hes-339m
Mada Soho Wireless Router Firmware
Mada Soho Wireless Router
ZTE Ox-330p Firmware
ZTE OX-330P
Zyxel Max218m Firmware
Zyxel Max218m
Zyxel Max218m1w Firmware
Zyxel Max218m1w
Zyxel Max218mw Firmware
Zyxel Max218mw
Zyxel Max308m Fimware
Zyxel Max308m
Zyxel Max318m Firmware
Zyxel Max318m
Zyxel Max338m Firmware
Zyxel Max338m

Event History

Jun 20, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2017-3216?

CVE-2017-3216 is classified as a high severity vulnerability due to the potential for a remote attacker to gain administrative access without authentication.

2

How does CVE-2017-3216 exploit authentication bypass?

CVE-2017-3216 allows an attacker to bypass authentication by changing the administrator password through a crafted POST request.

3

What devices are affected by CVE-2017-3216?

CVE-2017-3216 affects several WiMAX routers based on the MediaTek SDK including specific models from manufacturers like Greenpacket, Huawei, Mada, ZTE, and Zyxel.

4

How can CVE-2017-3216 be mitigated?

To mitigate CVE-2017-3216, ensure that your device firmware is updated to the latest version provided by the manufacturer to address this vulnerability.

5

Is CVE-2017-3216 a common vulnerability in WiMAX routers?

Yes, CVE-2017-3216 is a notable example of an authentication bypass vulnerability that has been identified in multiple WiMAX router models.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203