Vulnerability Description
The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to configure the cable modem via JavaScript in a victim's browser. The attacker can then configure the cable modem to port forward the modem's internal TELNET server, allowing external access to a root shell.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Technicolor | Tc7230 Steb Firmware | 0.1.25 |
| Technicolor | Tc7230 Steb | - |
Related Weaknesses (CWE)
References
- https://cablehaunt.comThird Party Advisory
- https://github.com/Lyrebirds/Cable-Haunt-Report/releases/download/2.4/report.pdfExploitIssue TrackingThird Party Advisory
- https://github.com/Lyrebirds/Fast8690-exploitThird Party Advisory
- https://cablehaunt.comThird Party Advisory
- https://github.com/Lyrebirds/Cable-Haunt-Report/releases/download/2.4/report.pdfExploitIssue TrackingThird Party Advisory
- https://github.com/Lyrebirds/Fast8690-exploitThird Party Advisory
FAQ
What is CVE-2019-19495?
CVE-2019-19495 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to configure the cable modem via JavaScript in a victim's browser. The attacker ca...
How severe is CVE-2019-19495?
CVE-2019-19495 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-19495?
Check the references section above for vendor advisories and patch information. Affected products include: Technicolor Tc7230 Steb Firmware, Technicolor Tc7230 Steb.