CVE-2014-8655 Information

Description

The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to bypass authentication and obtain sensitive information via an (a) admin or a (b) root value in the userData cookie in a request to (1) CmgwWirelessSecurity.xml (2) DocsisConfigFile.xml or (3) CmgwBasicSetup.xml in xml/ or (4) basicDDNS.html (5) basicLanUsers.html or (6) rootDesc.xml.

Reference

http://osvdb.org/show/osvdb/113837 http://packetstormsecurity.com/files/128860/CBN-CH6640E-CG6640E-Wireless-Gateway-XSS-CSRF-DoS-Disclosure.html http://www.exploit-db.com/exploits/35075 http://www.securityfocus.com/bid/70762 https://exchange.xforce.ibmcloud.com/vulnerabilities/98331

Share on: