CVE-2017-3216: Critical severity greenpacket ox350 firmware vulnerability
WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3216?
CVE-2017-3216 is classified as a high severity vulnerability due to the potential for a remote attacker to gain administrative access without authentication.
How does CVE-2017-3216 exploit authentication bypass?
CVE-2017-3216 allows an attacker to bypass authentication by changing the administrator password through a crafted POST request.
What devices are affected by CVE-2017-3216?
CVE-2017-3216 affects several WiMAX routers based on the MediaTek SDK including specific models from manufacturers like Greenpacket, Huawei, Mada, ZTE, and Zyxel.
How can CVE-2017-3216 be mitigated?
To mitigate CVE-2017-3216, ensure that your device firmware is updated to the latest version provided by the manufacturer to address this vulnerability.
Is CVE-2017-3216 a common vulnerability in WiMAX routers?
Yes, CVE-2017-3216 is a notable example of an authentication bypass vulnerability that has been identified in multiple WiMAX router models.