CVE-2017-14243: Utstar WA3002G4 Firmware

Critical severity, CVSS 9.8. EPSS: 14.8% chance of exploitation in the next 30 days.

An authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers to directly access administrative settings and obtain cleartext credentials from HTML source, as demonstrated by info.cgi, upload.cgi, backupsettings.cgi, pppoe.cgi, resetrouter.cgi, and password.cgi.

Affected products

  • Utstar WA3002G4 Firmware: version wa3002g4-0021.01 only

Published 2017-09-17. Last modified 2026-06-17.