CVE-2016-10042

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
29/06/2017
Last modified:
20/04/2025

Description

Authorization Bypass in the Web interface of Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) devices before R7.7 allows unauthorized reconfiguration of the static routing table via an unauthenticated HTTP request, leading to denial of service and information disclosure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:arcadyan:swisscom_internet-box_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arcadyan:swisscom_internet-box:-:*:*:*:light:*:*:*
cpe:2.3:h:arcadyan:swisscom_internet-box:-:*:*:*:plus:*:*:*
cpe:2.3:h:arcadyan:swisscom_internet-box:-:*:*:*:standard:*:*:*