CVE-2017-16953

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
01/12/2017
Last modified:
20/04/2025

Description

connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration or set up a malicious configuration via a GET request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zte:zxdsl_831cii_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxdsl_831cii:-:*:*:*:*:*:*:*