Junglewise Threat Intelligence

CVE-1999-0816: Motorola CableRouter unauthenticated remote configuration on port 1024

CVE-1999-0816 · Severity: critical · CVSS 10 · Published 1998-05-10

Executive brief

The Motorola CableRouter contains a critical security flaw that allows any person on the network to remotely access and modify the device's configuration. This router is used to manage internet connectivity, and an unauthorized user could take full control of the device to disrupt service or intercept data. Because no password or authentication is required to access the configuration port, the device is highly vulnerable to complete takeover.

Technical details

The Motorola CableRouter suffers from an authentication bypass or insecure default configuration where the management interface is exposed on TCP port 1024. A remote attacker can connect to this port over the network and gain full administrative access to the router's configuration settings. No credentials or prior authorization are required to exploit this vulnerability. This allows for a complete compromise of the device's integrity, confidentiality, and availability. The vulnerability was originally disclosed in 1998 and affects legacy Motorola CableRouter hardware.

Affected products

  • Motorola CableRouter

Timeline

  • 1998-05-10: disclosed: Initial public disclosure via Bugtraq and NVD.

References

Related threats