CVE-2009-4197

rpwizPppoe.htm in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 contains a form that does not disable the autocomplete setting for the password parameter, which makes it easier for local users or physically proximate attackers to obtain the password from web browsers that support autocomplete.
Configurations

Configuration 1 (hide)

cpe:2.3:h:huawei:mt882_v100t002b020_arg-t:firmware_3.7.9.98:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:huawei:mt882_modem_firmware:3.7.9.98:*:*:*:*:*:*:*
cpe:2.3:h:huawei:mt882_modem:v100r002b020_arg-t:*:*:*:*:*:*:*

History

21 Nov 2024, 01:09

Type Values Removed Values Added
References () http://www.exploit-db.com/exploits/10276 - Exploit () http://www.exploit-db.com/exploits/10276 - Exploit
References () http://www.securityfocus.com/bid/37194 - () http://www.securityfocus.com/bid/37194 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/54528 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/54528 -

Information

Published : 2009-12-04 11:30

Updated : 2024-11-21 01:09


NVD link : CVE-2009-4197

Mitre link : CVE-2009-4197

CVE.ORG link : CVE-2009-4197


JSON object : View

Products Affected

huawei

  • mt882_modem_firmware
  • mt882_modem
  • mt882_v100t002b020_arg-t