Authentication Bypass Vulnerability in WiMAX Routers with MediaTek SDK

Authentication Bypass Vulnerability in WiMAX Routers with MediaTek SDK

CVE-2017-3216 · HIGH Severity

AV:N/AC:L/AU:N/C:C/I:C/A:C

WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.

Learn more about our Cis Benchmark Audit For Ibm I.