CVE-2017-9521 describes a critical remote code execution vulnerability affecting specific Comcast firmware versions on Cisco DPC3939, DPC3939B, DPC3941T, and Arris TG1682G devices. The vulnerability stems from an unnecessarily exposed service that allows unauthenticated remote attackers to execute arbitrary code. With a CVSS score of 9.8 (Critical), this flaw carries the highest severity, indicating a network-based attack with low complexity, requiring no user interaction, and leading to complete compromise of confidentiality, integrity, and availability. While the specific service remains undisclosed, there is currently no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
dpc3939-p20-18-v303r20421733-160420a-cmcstCPE matchmatch criteria | cpe:2.3:o:cisco:dpc3939_firmware:dpc3939-p20-18-v303r20421733-160420a-cmcst:*:*:*:*:*:*:* | ||
dpc3939-p20-18-v303r20421746-170221a-cmcstCPE matchmatch criteria | cpe:2.3:o:cisco:dpc3939_firmware:dpc3939-p20-18-v303r20421746-170221a-cmcst:*:*:*:*:*:*:* | ||
dpc3939b-v303r204217-150321a-cmcstCPE matchmatch criteria | cpe:2.3:o:cisco:dpc3939b_firmware:dpc3939b-v303r204217-150321a-cmcst:*:*:*:*:*:*:* | ||
dpc3941_2.5s3_prod_seyCPE matchmatch criteria | cpe:2.3:o:cisco:dpc3941t_firmware:dpc3941_2.5s3_prod_sey:*:*:*:*:*:*:* | ||
10.0.132.sip.pc20.ctCPE matchmatch criteria | cpe:2.3:o:commscope:arris_tg1682g_firmware:10.0.132.sip.pc20.ct:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.