SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-4197

rpwizPppoe.htm in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 contains a form that does not disable the autocomplete setting for the password parameter, which makes it easier for local users or physically proximate attackers to obtain the…

MEDIUM 4.7EPSS 0.47%

Does this matter?

Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.

Description

rpwizPppoe.htm in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 contains a form that does not disable the autocomplete setting for the password parameter, which makes it easier for local users or physically proximate attackers to obtain the password from web browsers that support autocomplete.

CVSS 2.0
4.7 MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:N
EPSS
0.47% probability · 39th percentile
CISA KEV
Not listed
Affected
huawei/mt882 modem firmware · huawei/mt882 modem
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.