The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG599 device, when IP Passthrough mode is not used, configures WAN access to a caserver https service with the tech account and an empty password, which allows remote attackers to obtain root privileges by establishing a session on port 49955 and then installing new software, such as BusyBox with "nc -l" support.
원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-14116
원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-14116
댓글 0
번호 | 제목 | 글쓴이 | 날짜 | 조회 수 |
---|---|---|---|---|
512 | CVE-2017-12858 (libzip) | 관리자 | 2017.08.27 | 212 |
511 | CVE-2017-0133 | 관리자 | 2017.03.18 | 212 |
510 | CVE-2017-0098 | 관리자 | 2017.03.18 | 212 |
509 | CVE-2017-16605 | 관리자 | 2018.01.25 | 211 |
508 | CVE-2018-6000 | 관리자 | 2018.01.25 | 211 |
507 | CVE-2017-16643 | 관리자 | 2017.11.09 | 211 |
506 | CVE-2017-2866 | 관리자 | 2017.11.09 | 211 |
505 | CVE-2017-12719 | 관리자 | 2017.11.09 | 210 |
504 | CVE-2018-1000008 | 관리자 | 2018.01.25 | 209 |
503 | CVE-2018-0862 | 관리자 | 2018.01.25 | 209 |
502 | CVE-2017-7930 | 관리자 | 2017.08.27 | 209 |
501 | CVE-2017-0050 | 관리자 | 2017.03.18 | 209 |
500 | CVE-2017-0017 | 관리자 | 2017.03.18 | 209 |
499 | CVE-2016-6989 | 관리자 | 2016.10.14 | 209 |
498 | CVE-2017-16636 | 관리자 | 2017.11.09 | 208 |