Executive brief
SDMC NE6037 cable modem routers, used by internet service providers and home users for high-speed connectivity, contain a hardcoded password in their management software. An attacker can use this secret password to bypass security controls and gain full administrative control over the device. This allows them to monitor network traffic, disrupt internet service, or use the router as a jumping-off point to attack other devices on the home or corporate network.
Technical details
A hardcoded password vulnerability exists in the web management interface recovery endpoints (mgmt.php and npcmd.php) of SDMC NE6037 routers. The vulnerability is reachable via the unauthenticated public URL /cgi-bin/recovery.php, which maps to the handleConsoleRecovery function. By submitting the hardcoded credential 'YzVlY2UxMDc4MmEzYjYzNDM3OTY5NzkyYWQ1YWM2MGEK' via an HTTP GET request, an unauthenticated attacker can trigger the execution of iptables commands to open SSH and Telnet ports. When combined with the known default root password, this allows for complete remote system compromise. The issue affects firmware versions 7.1.6.0.25 and 7.1.6.1.9_B9.
Affected products
- SDMC NE6037 cable modem router 7.1.6.0.25, 7.1.6.1.9_B9
Timeline
- 2026-05-28: advisory: Vulnerability details and PoC published by security researcher kr3bz
- 2026-05-28: disclosed