CVE-2017-3216
Estado: ModificadaCrítica (9.8)—
WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 5.17%
- Percentil entre todas las CVEs puntuadas: 92
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (14)
Greenpacket — Ox350 FirmwareHuawei — Bm2022 FirmwareHuawei — Hes-309m FirmwareHuawei — Hes-319m2w FirmwareHuawei — Hes-319m FirmwareHuawei — Hes-339m FirmwareMada — Soho Wireless Router FirmwareZTE — Ox-330p FirmwareZyxel — Max218m1w FirmwareZyxel — Max218m FirmwareZyxel — Max218mw FirmwareZyxel — Max308m FimwareZyxel — Max318m FirmwareZyxel — Max338m Firmware
CWE
- CWE-306
- CWE-306
Referencias
- http://blog.sec-consult.com/2017/06/ghosts-from-past-authentication-bypass.html
- http://www.kb.cert.org/vuls/id/350135
- https://sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170607-0_Various_WiMAX_CPEs_Authentication_Bypass_v10.txt
- http://blog.sec-consult.com/2017/06/ghosts-from-past-authentication-bypass.html
- http://www.kb.cert.org/vuls/id/350135
- https://sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170607-0_Various_WiMAX_CPEs_Authentication_Bypass_v10.txt
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-3216",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "Huawei Technologies",
"product": "BM2022",
"versions": [
{
"status": "affected",
"version": "2.10.14"
}
]
},
{
"vendor": "Huawei Technologies",
"product": "HES-309M",
"versions": [
{
"status": "affected",
"version": "unknown"
}
]
},
{
"vendor": "Huawei Technologies",
"product": "HES-319M",
"versions": [
{
"status": "affected",
"version": "unknown"
}
]
},
{
"vendor": "Huawei Technologies",
"product": "HES-319M2W",
"versions": [
{
"status": "affected",
"version": "unknown"
}
]
},
{
"vendor": "Huawei Technologies",
"product": "HES-339M",
"versions": [
{
"status": "affected",
"version": "unknown"
}
]
},
{
"vendor": "Green Packet",
"product": "OX350",
"versions": [
{
"status": "affected",
"version": "unknown"
}
]
},
{
"vendor": "ZTE",
"product": "OX-330P",
"versions": [
{
"status": "affected",
"version": "unknown"
}
]
},
{
"vendor": "ZyXEL",
"product": "MAX218M",
"versions": [
{
"status": "affected",
"version": "2.00(UXG.0)D0"
}
]
},
{
"vendor": "ZyXEL",
"product": "MAX218M1W",
"versions": [
{
"status": "affected",
"version": "2.00(UXE.3)D0"
}
]
},
{
"vendor": "ZyXEL",
"product": "MAX218MW",
"versions": [
{
"status": "affected",
"version": "2.00(UXD.2)D0"
}
]
},
{
"vendor": "ZyXEL",
"product": "MAX308M",
"versions": [
{
"status": "affected",
"version": "2.00(UUA.3)D0"
}
]
},
{
"vendor": "ZyXEL",
"product": "MAX318M",
"versions": [
{
"status": "affected",
"version": "unknown"
}
]
},
{
"vendor": "ZyXEL",
"product": "MAX338M",
"versions": [
{
"status": "affected",
"version": "unknown"
}
]
},
{
"vendor": "MADA",
"product": "Soho Wireless Router",
"versions": [
{
"status": "affected",
"version": "2.10.13"
}
]
}
]
}
],
"published": "2017-06-20T00:29:00.267",
"references": [
{
"url": "http://blog.sec-consult.com/2017/06/ghosts-from-past-authentication-bypass.html",
"tags": [
"Third Party Advisory"
],
"source": "cret@cert.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/350135",
"tags": [
"Mitigation",
"Third Party Advisory",
"US Government Resource"
],
"source": "cret@cert.org"
},
{
"url": "https://sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170607-0_Various_WiMAX_CPEs_Authentication_Bypass_v10.txt",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cret@cert.org"
},
{
"url": "http://blog.sec-consult.com/2017/06/ghosts-from-past-authentication-bypass.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/350135",
"tags": [
"Mitigation",
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170607-0_Various_WiMAX_CPEs_Authentication_Bypass_v10.txt",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cret@cert.org",
"description": [
{
"lang": "en",
"value": "CWE-306"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-306"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request."
},
{
"lang": "es",
"value": "Los routers WiMAX basados en MediaTek SDK (libmtk) que emplean un plugin httpd personalizado son vulnerables a una omisión de autenticación. Esto permite que un atacante remoto no autenticado obtenga acceso de administrador al dispositivo realizando un cambio de contraseña de administrador en el dispositivo mediante una petición POST manipulada."
}
],
"lastModified": "2026-06-17T01:17:45.190",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:greenpacket:ox350_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0A81F52A-6DD6-4631-8733-9E47C6DAC87F"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:greenpacket:ox350:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "327A0834-F46C-4E74-925C-D3EA1DE6941E"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:bm2022_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A779549C-E231-44F7-94AB-AE12D63641E2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:bm2022:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B4F75E1B-DAA2-495B-B1CA-5228E3819F79"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:hes-309m_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F7239E02-7A4A-476B-AAF9-EF72D3A9407F"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:hes-309m:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7DA39FE7-9B9E-443A-B41A-CADDCC4F544C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:hes-319m_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "36923E11-A6AA-41C5-A3F7-8350A9053D86"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:hes-319m:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0863C568-5A6A-4961-B628-299D0E7A54E7"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:hes-319m2w_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "03234F0A-1CD6-4087-829A-2CB15022A200"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:hes-319m2w:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4E48D770-DD54-4980-A8C4-359CF5DEF7A6"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:hes-339m_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A3294BDE-B2FB-41DD-A6DE-B08B5278AA1B"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:hes-339m:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "AAF51DF4-56DB-4EE9-95E4-FCFE040B3770"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:mada:soho_wireless_router_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16AB1DA5-2DB6-4892-896B-F630B0765989"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:mada:soho_wireless_router:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "33FD7BD1-B005-4F24-962D-5337AFD740AE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zte:ox-330p_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB20B496-6386-49B4-9103-45729D61F435"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zte:ox-330p:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "952793D7-1F57-42F3-9379-F9A31289E4AE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:max218m_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F0F66ADE-21DF-49F0-A404-CE3EED23E178"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:max218m:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "CC4B3ACA-0373-4574-AEE1-16E4B8D1E3BA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:max218m1w_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4DE102CD-FFFA-4E9C-94E6-DDD3E1673A45"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:max218m1w:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1DFAEDFB-E181-4B91-81A6-D105A401870A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:max218mw_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DE2DF253-7D1D-4C43-A209-681A8663044C"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:max218mw:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1194BED0-101B-4B23-BA0A-BE635F5FA7F8"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:max308m_fimware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4C0C8A2C-AA09-4326-A369-07895094BB0A"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:max308m:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5DF88B7A-4919-455F-804F-6C1A709B8147"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:max318m_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "52093480-956D-47D5-998F-68CE3CE69BDF"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:max318m:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "55246D23-CF70-4BE5-899D-72AE038DE262"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:max338m_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9523A7F1-4F6C-4597-BC02-BA3FE729530D"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:max338m:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "34CAEB05-E93D-45BB-9742-00CDBBCFBDE5"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cret@cert.org"
}