High severity7.5NVD Advisory· Published Dec 1, 2017· Updated May 13, 2026
CVE-2017-16953
CVE-2017-16953
Description
connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration or set up a malicious configuration via a GET request.
Affected products
1- cpe:2.3:o:zte:zxdsl_831cii_firmware:-:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- packetstormsecurity.com/files/145121/ZTE-ZXDSL-831-Unauthorized-Configuration-Access-Bypass.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/43188/nvdThird Party AdvisoryVDB Entry
- support.zte.com.cn/support/news/LoopholeInfoDetail.aspxnvd
News mentions
0No linked articles in our index yet.