4.7
CVSSv2

CVE-2009-4197

Published: 04/12/2009 Updated: 17/08/2017
CVSS v2 Base Score: 4.7 | Impact Score: 6.9 | Exploitability Score: 3.4
VMScore: 475
Vector: AV:L/AC:M/Au:N/C:C/I:N/A:N

Vulnerability Summary

rpwizPppoe.htm in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 contains a form that does not disable the autocomplete setting for the password parameter, which makes it easier for local users or physically proximate malicious users to obtain the password from web browsers that support autocomplete.

Vulnerable Product Search on Vulmon Subscribe to Product

huawei mt882_modem_firmware 3.7.9.98

huawei mt882_modem v100r002b020_arg-t

Exploits

# Version: V100R002B020 ARG-T # Firmware Release: 37998 #Greets to my bests friends: DeepLook, [R00T], systemfailure, Ciber34, ANDSQLiTor, La_Peke # #Greets to friend: Scuarplex, Crl, KiKoArg, ZeRO, DNSX, PunkiD # DecodeX01[at]gmail[dot]com # Target device ip 10002:80 (default ip:port) Server information ...