CVE-2017-3216
WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.
Published:Jun 20, 2017
Last Modified:Apr 20, 2025
EPS:Jun 20, 2017
EPSS Score:0.03167
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Greenpacket
Product
Ox350
Greenpacket
Ox350
Vendor
Greenpacket
Product
Ox350 Firmware
Greenpacket
Ox350 Firmware
Vendor
Huawei
Product
Bm2022
Huawei
Bm2022
Vendor
Huawei
Product
Bm2022 Firmware
Huawei
Bm2022 Firmware
Vendor
Huawei
Product
Hes-309m
Huawei
Hes-309m
Vendor
Huawei
Product
Hes-309m Firmware
Huawei
Hes-309m Firmware
Vendor
Huawei
Product
Hes-319m
Huawei
Hes-319m
Vendor
Huawei
Product
Hes-319m2w
Huawei
Hes-319m2w
Vendor
Huawei
Product
Hes-319m2w Firmware
Huawei
Hes-319m2w Firmware
Vendor
Huawei
Product
Hes-319m Firmware
Huawei
Hes-319m Firmware
Vendor
Huawei
Product
Hes-339m
Huawei
Hes-339m
Vendor
Huawei
Product
Hes-339m Firmware
Huawei
Hes-339m Firmware
Vendor
Mada
Product
Soho Wireless Router
Mada
Soho Wireless Router
Vendor
Mada
Product
Soho Wireless Router Firmware
Mada
Soho Wireless Router Firmware
Vendor
Zte
Product
Ox-330p
Zte
Ox-330p
Vendor
Zte
Product
Ox-330p Firmware
Zte
Ox-330p Firmware
Vendor
Zyxel
Product
Max218m
Zyxel
Max218m
Vendor
Zyxel
Product
Max218m1w
Zyxel
Max218m1w
Vendor
Zyxel
Product
Max218m1w Firmware
Zyxel
Max218m1w Firmware
Vendor
Zyxel
Product
Max218m Firmware
Zyxel
Max218m Firmware
Vendor
Zyxel
Product
Max218mw
Zyxel
Max218mw
Vendor
Zyxel
Product
Max218mw Firmware
Zyxel
Max218mw Firmware
Vendor
Zyxel
Product
Max308m
Zyxel
Max308m
Vendor
Zyxel
Product
Max308m Fimware
Zyxel
Max308m Fimware
Vendor
Zyxel
Product
Max318m
Zyxel
Max318m
Vendor
Zyxel
Product
Max318m Firmware
Zyxel
Max318m Firmware
Vendor
Zyxel
Product
Max338m
Zyxel
Max338m
Vendor
Zyxel
Product
Max338m Firmware
Zyxel
Max338m Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
