PoC Index

CVE-2014-8655

MEDIUM 5.0EPSS 7.4%

The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to bypass authentication and obtain sensitive information via an (a) admin or a (b) root value in the userData cookie in a request to (1) CmgwWirelessSecurity.xml, (2) DocsisConfigFile.xml, or (3) CmgwBasicSetup.xml in xml/ or (4) basicDDNS.html, (5) basicLanUsers.html, or (6) rootDesc.xml.

CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
7.38% chance of exploitation in the next 30 days, 94th percentile
Published
2014-11-06
Updated
2024-08-06

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related