Vulnerabilities > CVE-2009-4197 - Cross-Site Scripting and Information Disclosure vulnerability in Huawei Mt882 Modem and Mt882 Modem Firmware

047910
CVSS 4.7 - MEDIUM
Attack vector
LOCAL
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
NONE
Availability impact
NONE
local
huawei
exploit available

Summary

rpwizPppoe.htm in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 contains a form that does not disable the autocomplete setting for the password parameter, which makes it easier for local users or physically proximate attackers to obtain the password from web browsers that support autocomplete.

Exploit-Db

descriptionHuawei MT882 Modem/Router Multiple Vulnerabilities. CVE-2009-4196,CVE-2009-4197. Webapps exploit for hardware platform
fileexploits/hardware/webapps/10276.txt
idEDB-ID:10276
last seen2016-02-01
modified2009-12-03
platformhardware
port
published2009-12-03
reporterDecodeX01
sourcehttps://www.exploit-db.com/download/10276/
titleHuawei MT882 Modem/Router Multiple Vulnerabilities
typewebapps