The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a cleartext password in a POST request on port 80, as demonstrated by the Password field to the xml/setter.xml URI.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Connect_box_eurodocsis_firmware | Upc | ch7465lg-ncip-6.12.18.25-2p6-nosh (including) | ch7465lg-ncip-6.12.18.25-2p6-nosh (including) |