CVE-2018-9249

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
04/04/2018
Last modified:
21/05/2018

Description

FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScript code in the response to an unauthenticated request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:fiberhome:vdsl2_modem_hg_150-ub_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:fiberhome:vdsl2_modem_hg_150-ub:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools