CVE-2017-3216: Greenpacket OX350 Firmware

Critical severity, CVSS 9.8. EPSS: 5.2% chance of exploitation in the next 30 days.

WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.

Affected products

  • Greenpacket OX350 Firmware: affected versions not specified
  • Huawei BM2022 Firmware: affected versions not specified
  • Huawei Hes-309m Firmware: affected versions not specified
  • Huawei Hes-319m2w Firmware: affected versions not specified
  • Huawei Hes-319m Firmware: affected versions not specified
  • Huawei Hes-339m Firmware: affected versions not specified
  • Mada Soho Wireless Router Firmware: affected versions not specified
  • ZTE Ox-330p Firmware: affected versions not specified
  • Zyxel MAX218M1W Firmware: affected versions not specified
  • Zyxel MAX218M Firmware: affected versions not specified
  • Zyxel MAX218MW Firmware: affected versions not specified
  • Zyxel MAX308M Fimware: affected versions not specified
  • Zyxel MAX318M Firmware: affected versions not specified
  • Zyxel MAX338M Firmware: affected versions not specified

Published 2017-06-20. Last modified 2026-06-17.