HIGH
cgi/b on the BT Home Hub router allows remote attackers to bypass authentication, and read or modify administrative settings or make arbitrary VoIP telephone calls, by placing a character at the end of the PATH_INFO, as demonstrated by (1) %5C (encoded backslash), (2) '%' (percent), and (3) '~' (tilde)
Published Mar 13, 2008
7.5
HIGHCVSS 2.0
EPSS 1.68%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.