CVE-2009-4197 describes a vulnerability in the Huawei MT882 V100R002B020 ARG-T modem/router firmware 3.7.9.98, where the rpwizPppoe.htm form fails to disable the autocomplete setting for the password field. This flaw allows local or physically proximate attackers to easily retrieve stored passwords from web browsers that support autocomplete. The vulnerability has a CVSS score of 4.7, indicating medium severity, with a local attack vector and high confidentiality impact. While an ExploitDB entry exists (EDB-10276) mentioning multiple vulnerabilities in the device, there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage for this specific CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.7.9.98CPE matchmatch criteria | cpe:2.3:a:huawei:mt882_modem_firmware:3.7.9.98:*:*:*:*:*:*:* | ||
v100r002b020_arg-tCPE matchmatch criteria | cpe:2.3:h:huawei:mt882_modem:v100r002b020_arg-t:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.