CVE-2016-9497 describes an authentication bypass vulnerability affecting various Hughes high-performance broadband satellite modem models, including the HN7740S, DW7000, HN7000S, and HN7000SM. The vulnerability stems from an unauthenticated Telnet service accessible on port 1953, allowing remote attackers to execute administrative commands. With a CVSS v3.0 score of 8.8 (High), this vulnerability allows an adjacent network attacker to achieve high impact on confidentiality, integrity, and availability, including the ability to reboot affected modems, with low attack complexity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.9.0.34CPE matchmatch criteria | cpe:2.3:o:hughes:hn7740s_firmware:6.9.0.34:*:*:*:*:*:*:* | ||
6.9.0.34CPE matchmatch criteria | cpe:2.3:o:hughes:dw7000_firmware:6.9.0.34:*:*:*:*:*:*:* | ||
6.9.0.34CPE matchmatch criteria | cpe:2.3:o:hughes:hn7000s_firmware:6.9.0.34:*:*:*:*:*:*:* | ||
6.9.0.34CPE matchmatch criteria | cpe:2.3:o:hughes:hn7000sm_firmware:6.9.0.34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.