Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-9476 PoC — Cisco DPC3939和Arris TG1682G 信息泄露漏洞

Source
Associated Vulnerability
Title:Cisco DPC3939和Arris TG1682G 信息泄露漏洞 (CVE-2017-9476)
Description:The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); and Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices makes it easy for remote attackers to determine the hidden SSID and passphrase for a Home Security Wi-Fi network.
Description
Hidden AP with Deterministic Credentials
Readme
# CVE-2017-9476

Hidden AP with Deterministic Credentials.

## Compiling

```
    cc xhscmmac2psk.c -o xhscmmac2psk
```

## Usage

```
    ./xhscmmac2psk <valid Cable Modem mac address>
```

The algorithm has been also added to [PSKracker](https://github.com/soxrok2212/PSKracker/commit/f099690ec5fdeee74b6e8ded80812dac5a415557).

## References

- [CVE-2017-9476](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9476)
- [Bastille-18.home-security-wifi-network.txt](https://github.com/BastilleResearch/CableTap/blob/master/doc/advisories/bastille-18.home-security-wifi-network.txt)
- [DEFCON 25 whitepaper](https://github.com/BastilleResearch/CableTap/blob/master/doc/pdf/DEFCON-25-Marc-Newlin-CableTap-White-Paper.pdf)
- [DEFCON 25 slides](https://github.com/BastilleResearch/CableTap/blob/master/doc/pdf/DEFCON-25-Marc-Newlin-CableTap-Slides.pdf)
File Snapshot

[4.0K] /data/pocs/74f3f93097d7818243f962c19da9e48b9828ba96 ├── [ 854] README.md └── [4.8K] xhscmmac2psk.c 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →