Access Control Vulnerability in Toshiba Home Gateway Products
CVE-2017-2235
9.8CRITICAL
Summary
The vulnerability in Toshiba Home Gateway devices HEM-GW16A and HEM-GW26A allows attackers to bypass access restrictions, enabling them to change the administrator account password through unspecified vectors. This can potentially compromise the security and integrity of the device, leading to unauthorized control over network settings and connected devices.
Affected Version(s)
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier
Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved