Cox Biz Auth-Bypass Bug Exposes Millions of Devices to Takeover
ID: 59a99433-eb4f-5412-8809-7da6ed860348
STIX ID: report--59a99433-eb4f-5412-8809-7da6ed860348
Feed Name: Dark Reading
Date Published: 2024-06-04
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researcher Sam Curry discovered an authorization-bypass flaw in Cox Communications' back-end API infrastructure that allowed replaying HTTP requests across more than 700 exposed endpoints to obtain business-customer UUIDs, PII, device MAC addresses, Wi‑Fi passwords, and to execute commands or take over modems; the issue was rooted in a Spring proxying error, was reported on March 4 and patched by Cox the next day, and Cox reported no evidence of abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
