Vulnerability Description
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, lacks authentication. An unauthenticated user may send an HTTP GET request to http://[ip]/com/gatewayreset or http://[ip]/cgi/reboot.bin to cause the modem to reboot.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hughes | Hn7740S Firmware | 6.9.0.34 |
| Hughes | Hn7740S | - |
| Hughes | Dw7000 Firmware | 6.9.0.34 |
| Hughes | Dw7000 | - |
| Hughes | Hn7000S Firmware | 6.9.0.34 |
| Hughes | Hn7000S | - |
| Hughes | Hn7000Sm Firmware | 6.9.0.34 |
| Hughes | Hn7000Sm | - |
Related Weaknesses (CWE)
References
- https://www.kb.cert.org/vuls/id/614751Third Party AdvisoryUS Government Resource
- https://www.securityfocus.com/bid/96244Third Party AdvisoryVDB Entry
- https://www.kb.cert.org/vuls/id/614751Third Party AdvisoryUS Government Resource
- https://www.securityfocus.com/bid/96244Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-9496?
CVE-2016-9496 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, lacks authentication. An unauthenticated user may send an HTTP GET request to http://[ip]/com/gatewayreset or http...
How severe is CVE-2016-9496?
CVE-2016-9496 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-9496?
Check the references section above for vendor advisories and patch information. Affected products include: Hughes Hn7740S Firmware, Hughes Hn7740S, Hughes Dw7000 Firmware, Hughes Dw7000, Hughes Hn7000S Firmware.