CWE
306
Advisory Published
Updated

CVE-2017-3216

First published: Tue Jun 20 2017(Updated: )

WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.

Credit: cret@cert.org

Affected SoftwareAffected VersionHow to fix
Greenpacket Ox350 Firmware
Greenpacket Ox350 Firmware
Huawei Bm2022
Huawei Bm2022 Firmware
Huawei Hes-309m
Huawei Hes-309m Firmware
Huawei Hes-319m2w Firmware
Huawei Hes-319m
Hes-319M2W
Hes-319M2W
Huawei Hes-339m
Huawei Hes-339m Firmware
Mada Soho Wireless Router Firmware
Lenovo ThinkPad Stack Wireless Router firmware
ZTE OX-330P Firmware
ZTE OX-330P Firmware
Zyxel Max218m1w Firmware
Zyxel Max218m1w Firmware
Zyxel Max218m1w
Zyxel Max218m1w Firmware
Zyxel Max218m1w Firmware
Zyxel Max218MW Firmware
Zyxel Max308m Firmware
Zyxel Max308m Firmware
Zyxel Max318m Firmware
Zyxel Max318m Firmware
Zyxel Max338m
Zyxel Max338m Firmware

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2017-3216?

    CVE-2017-3216 is classified as a high severity vulnerability due to the potential for a remote attacker to gain administrative access without authentication.

  • How does CVE-2017-3216 exploit authentication bypass?

    CVE-2017-3216 allows an attacker to bypass authentication by changing the administrator password through a crafted POST request.

  • What devices are affected by CVE-2017-3216?

    CVE-2017-3216 affects several WiMAX routers based on the MediaTek SDK including specific models from manufacturers like Greenpacket, Huawei, Mada, ZTE, and Zyxel.

  • How can CVE-2017-3216 be mitigated?

    To mitigate CVE-2017-3216, ensure that your device firmware is updated to the latest version provided by the manufacturer to address this vulnerability.

  • Is CVE-2017-3216 a common vulnerability in WiMAX routers?

    Yes, CVE-2017-3216 is a notable example of an authentication bypass vulnerability that has been identified in multiple WiMAX router models.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203