CVE-2017-3216: Greenpacket OX350 Firmware
Critical severity, CVSS 9.8. EPSS: 5.2% chance of exploitation in the next 30 days.
WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.
Affected products
- Greenpacket OX350 Firmware: affected versions not specified
- Huawei BM2022 Firmware: affected versions not specified
- Huawei Hes-309m Firmware: affected versions not specified
- Huawei Hes-319m2w Firmware: affected versions not specified
- Huawei Hes-319m Firmware: affected versions not specified
- Huawei Hes-339m Firmware: affected versions not specified
- Mada Soho Wireless Router Firmware: affected versions not specified
- ZTE Ox-330p Firmware: affected versions not specified
- Zyxel MAX218M1W Firmware: affected versions not specified
- Zyxel MAX218M Firmware: affected versions not specified
- Zyxel MAX218MW Firmware: affected versions not specified
- Zyxel MAX308M Fimware: affected versions not specified
- Zyxel MAX318M Firmware: affected versions not specified
- Zyxel MAX338M Firmware: affected versions not specified
Published 2017-06-20. Last modified 2026-06-17.