Saturday, January 18, 2025
HomeCVE/vulnerabilityCable Haunt - Critical Vulnerability Let Hackers Control Cable Modems Remotely

Cable Haunt – Critical Vulnerability Let Hackers Control Cable Modems Remotely

Published on

SIEM as a Service

Follow Us on Google News

Researchers discovered as critical vulnerability dubbed Cable Haunt affects cable modems from different manufacturers across the globe.

The vulnerability enables a remote attacker to gain complete control over the modem through its endpoint.

Successful exploitation allows attackers to intercept private messages, redirect traffic, or participate in botnets.

Cable Haunt vulnerability was discovered by a team of Danish security researchers in Broadcom cable modems.

Cable Haunt Attacks Middleware

The vulnerability targets the middleware running on the chip used in the Broadcom cable modems, the middleware is the real-time operating system in cable modems that runs all the networking tasks.

It affects multiple vendors as the same software being used by various cable modem manufacturers to create their cable modem firmware.

All the traffic goes through the cable modem middleware (CM), by gaining control over it attackers can manipulate any traffic going through the modem.

How the Attack Works

The attack is a two-step process: An attacker should gain access to the vulnerable endpoints through local networks such as browsers, this can be done by making the victim opening a malicious link in a browser.

The exploit not only the browser, but it can also be executed in any place where running the code can reach IP on the local network.

Next, the attacker needs to hit the vulnerable endpoint with buffer overflow attack, by creating a crafted message a remote attacker can manipulate the modem to execute arbitrary code specified by a remote attacker.

Once the code executed attackers can gain complete control over the modem and can perform various operation such as

  • Change default DNS server
  • Conduct remote man-in-the-middle attacks
  • Hot-swap code or even the entire firmware
  • Upload, flash, and upgrade firmware silently
  • Disable ISP firmware upgrade
  • Change every config file and settings
  • Get and Set SNMP OID values
  • Change all associated MAC Addresses
  • Change serial numbers
  • Be exploited in botnet

Modems Affected

Researchers estimated that “more than 200 million modems may be or might have been vulnerable in Europe alone and there is no way to track the vulnerability spread”.

Here is the list of vulnerable modems:

ModelFirmware VersionPortDefault Credentials
Sagemcom F@st 389050.10.19.*6080spectrum:spectrum (Authorization: Basic)
Sagemcom F@st 3686SIP_3.428.0-*6080spectrum:spectrum (Authorization: Basic)
Technicolor TC7230STEB 01.258080No authorization needed
Netgear C6250EMRV2.01.058080No authorization needed
Netgear CG3700EMRV2.01.038080No authorization needed
Sagemcom F@st 389005.76.6.3aunknownunknown
Sagemcom F@st 36864.83.0unknownunknown
COMPAL 7284E5.510.5.11unknownunknown
COMPAL 7486E5.510.5.11unknownunknown
Netgear CG3700EMRV2.01.058080No authorization needed

As the cable Haunt allows attackers to gain complete access to the modem it is hard to detect the infection as the attacker can hide the tracks.

Researchers also stated that there is no evidence of active exploitation, and this attack doesn’t break SSL/TLS encryption.

A tool has been released to check whether your modem is vulnerable, the tool can be downloaded from here.

Here you find the detailed Technical report explaining the Cable Haunt vulnerability and the PoC of the attack.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Hackers Easily Bypass Active Directory Group Policy to Allow Vulnerable NTLMv1 Auth Protocol

Researchers have discovered a critical flaw in Active Directory’s NTLMv1 mitigation strategy, where misconfigured...

AWS Warns of Multiple Vulnerabilities in Amazon WorkSpaces, Amazon AppStream 2.0, & Amazon DCV

Amazon Web Services (AWS) has issued a critical security advisory highlighting vulnerabilities in specific...

FlowerStorm PaaS Platform Attacking Microsoft Users With Fake Login Pages

Rockstar2FA is a PaaS kit that mimics the legitimate credential-request behavior of cloud/SaaS platforms....

New Tool Unveiled to Scan Hacking Content on Telegram

A Russian software developer, aided by the National Technology Initiative, has introduced a groundbreaking...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

AWS Warns of Multiple Vulnerabilities in Amazon WorkSpaces, Amazon AppStream 2.0, & Amazon DCV

Amazon Web Services (AWS) has issued a critical security advisory highlighting vulnerabilities in specific...

PoC Exploit Released for Ivanti Connect Secure RCE Vulnerability

A serious security flaw has been identified in Ivanti Connect Secure, designated as CVE-2025-0282, which...

CISA Warns of Aviatrix Controllers OS Command Injection Vulnerability Exploited in Wild

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding a...