Cox fixed an API auth bypass exposing millions of modems to attacks
ID: f0ff9afd-c469-52d2-a719-8cfc99ff8b21
STIX ID: report--f0ff9afd-c469-52d2-a719-8cfc99ff8b21
Feed Name: Bleeping Computer
Cox Communications patched an authentication-bypass vulnerability discovered by researcher Sam Curry that exposed over 700 backend APIs and could have allowed attackers to reset millions of Cox-supplied modems, access customers' PII (names, emails, phone numbers, MAC addresses), retrieve connected devices' Wi‑Fi passwords, and execute administrative commands; Cox removed the exposed API calls within six hours of the report, patched the flaw the next day, and said it found no evidence the issue had been exploited prior to disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
