Vulnerability Description
Deutsche Telekom (T-com) Speedport W 700v uses JavaScript delays for invalid authentication attempts to the CGI script, which allows remote attackers to bypass the delays and conduct brute-force attacks via direct calls to the authentication CGI script.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| T-Com | Speedport W 700V | All versions |
References
- http://osvdb.org/36011
- http://secunia.com/advisories/25266Vendor Advisory
- http://securityreason.com/securityalert/2705
- http://www.devtarget.org/speedport700-advisory-05-2007.txtVendor Advisory
- http://www.securityfocus.com/archive/1/468361/100/0/threaded
- http://www.securityfocus.com/bid/23967
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34334
- http://osvdb.org/36011
- http://secunia.com/advisories/25266Vendor Advisory
- http://securityreason.com/securityalert/2705
- http://www.devtarget.org/speedport700-advisory-05-2007.txtVendor Advisory
- http://www.securityfocus.com/archive/1/468361/100/0/threaded
- http://www.securityfocus.com/bid/23967
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34334
FAQ
What is CVE-2007-2649?
CVE-2007-2649 is a vulnerability with a CVSS score of 7.8 (HIGH). Deutsche Telekom (T-com) Speedport W 700v uses JavaScript delays for invalid authentication attempts to the CGI script, which allows remote attackers to bypass the delays and conduct brute-force attac...
How severe is CVE-2007-2649?
CVE-2007-2649 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-2649?
Check the references section above for vendor advisories and patch information. Affected products include: T-Com Speedport W 700V.