Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the 31 parameter in a NewUser function, which is not filtered by the modem when creating the account, but cannot be deleted by the administrator, possibly due to cleansing that occurs in the administrator interface.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Speedtouch | Thomson | 516_5.3.2.6.0 (including) | 516_5.3.2.6.0 (including) |
| Speedtouch | Thomson | 530_5.3.2.6.0 (including) | 530_5.3.2.6.0 (including) |
| Speedtouch | Thomson | 536_5.3.2.6.0 (including) | 536_5.3.2.6.0 (including) |
| Speedtouch | Thomson | 546_5.3.2.6.0 (including) | 546_5.3.2.6.0 (including) |
| Speedtouch | Thomson | 576_5.3.2.6.0 (including) | 576_5.3.2.6.0 (including) |
| Speedtouch | Thomson | 580_5.3.2.6.0 (including) | 580_5.3.2.6.0 (including) |
| Speedtouch | Thomson | 585_5.3.2.6.0 (including) | 585_5.3.2.6.0 (including) |