CVE Feed

    Dashboard / CVE / CVE-2017-3216

    CVE-2017-3216

    WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.

    Published:Jun 20, 2017
    Last Modified:Apr 20, 2025
    EPS:Jun 20, 2017
    EPSS Score:0.03167
    CVSS Score:9.8

    Affected Products

    Vendor
    Greenpacket
    Product
    Ox350
    Vendor
    Greenpacket
    Product
    Ox350 Firmware
    Vendor
    Huawei
    Product
    Bm2022
    Vendor
    Huawei
    Product
    Bm2022 Firmware
    Vendor
    Huawei
    Product
    Hes-309m
    Vendor
    Huawei
    Product
    Hes-309m Firmware
    Vendor
    Huawei
    Product
    Hes-319m
    Vendor
    Huawei
    Product
    Hes-319m2w
    Vendor
    Huawei
    Product
    Hes-319m2w Firmware
    Vendor
    Huawei
    Product
    Hes-319m Firmware
    Vendor
    Huawei
    Product
    Hes-339m
    Vendor
    Huawei
    Product
    Hes-339m Firmware
    Vendor
    Mada
    Product
    Soho Wireless Router
    Vendor
    Mada
    Product
    Soho Wireless Router Firmware
    Vendor
    Zte
    Product
    Ox-330p
    Vendor
    Zte
    Product
    Ox-330p Firmware
    Vendor
    Zyxel
    Product
    Max218m
    Vendor
    Zyxel
    Product
    Max218m1w
    Vendor
    Zyxel
    Product
    Max218m1w Firmware
    Vendor
    Zyxel
    Product
    Max218m Firmware
    Vendor
    Zyxel
    Product
    Max218mw
    Vendor
    Zyxel
    Product
    Max218mw Firmware
    Vendor
    Zyxel
    Product
    Max308m
    Vendor
    Zyxel
    Product
    Max308m Fimware
    Vendor
    Zyxel
    Product
    Max318m
    Vendor
    Zyxel
    Product
    Max318m Firmware
    Vendor
    Zyxel
    Product
    Max338m
    Vendor
    Zyxel
    Product
    Max338m Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High