Cox fixed an API auth bypass exposing millions of modems to attacks

Started by ixsky,

Previous topic - Next topic

ixsky

Cox fixed an API auth bypass exposing millions of modems to attacks

​Cox Communications has fixed an authorization bypass vulnerability that enabled remote attackers to abuse exposed backend APIs to reset millions of modems' settings and steal customers' sensitive personal information. [...]

Source: Cox fixed an API auth bypass exposing millions of modems to attacks