CVE-2019-19967

The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a cleartext password in a POST request on port 80, as demonstrated by the Password field to the xml/setter.xml URI.
References
Link Resource
https://github.com/filipi86/ConnectBoxDOCSIS-3.0 Exploit Third Party Advisory
Configurations

Configuration 1


Information

Published : 2019-12-25 10:15

Updated : 2020-01-08 09:26


NVD link : CVE-2019-19967

Mitre link : CVE-2019-19967

CWE
CWE-319

Cleartext Transmission of Sensitive Information