CVE-2017-2235 describes a critical vulnerability in Toshiba Home gateway HEM-GW16A (firmware HEM-GW16A-FW-V1.2.0 and earlier) and HEM-GW26A (firmware HEM-GW26A-FW-V1.2.0 and earlier) devices. This flaw allows an unauthenticated attacker to bypass access restrictions and change the administrator account password through unspecified vectors. With a CVSSv3 score of 9.8 (Critical), this vulnerability is easily exploitable over the network with low attack complexity, requiring no user interaction. A successful exploit grants an attacker full control over the device, leading to high impacts on confidentiality, integrity, and availability. Despite its critical severity, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, indicating a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.2.0CPE matchmatch criteria | cpe:2.3:o:toshiba:hem-gw16a_firmware:*:*:*:*:*:*:*:* | ||
<= 1.2.0CPE matchmatch criteria | cpe:2.3:o:toshiba:hem-gw26a_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.