Vulnerability CVE-2014-8655


Published: 2014-11-06

Description:
The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to bypass authentication and obtain sensitive information via an (a) admin or a (b) root value in the userData cookie in a request to (1) CmgwWirelessSecurity.xml, (2) DocsisConfigFile.xml, or (3) CmgwBasicSetup.xml in xml/ or (4) basicDDNS.html, (5) basicLanUsers.html, or (6) rootDesc.xml.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Compal broadband networks -> Firmware 
Compal broadband networks -> Cg6640e wireless gateway 
Compal broadband networks -> Ch664oe wireless gateway 

 References:
http://packetstormsecurity.com/files/128860/CBN-CH6640E-CG6640E-Wireless-Gateway-XSS-CSRF-DoS-Disclosure.html
http://www.exploit-db.com/exploits/35075
http://www.securityfocus.com/bid/70762
https://exchange.xforce.ibmcloud.com/vulnerabilities/98331

Copyright 2024, cxsecurity.com

 

Back to Top