Vulnerabilities > CVE-2005-0494 - Denial-Of-Service vulnerability in Thomson Cable Modem Tcw690

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
thomson
exploit available

Summary

The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct POST request.

Vulnerable Configurations

Part Description Count
Hardware
Thomson
1

Exploit-Db

descriptionThomson TCW690 POST Password Validation Exploit. CVE-2005-0494. Remote exploit for hardware platform
idEDB-ID:829
last seen2016-01-31
modified2005-02-19
published2005-02-19
reporterMurDoK
sourcehttps://www.exploit-db.com/download/829/
titleThomson TCW690 POST Password Validation Exploit