Page 1 of 1

Cablehaunt vulnerability in Sonic modems?

Posted: Thu Jan 09, 2020 12:51 pm
by jeremy
I recently heard about a vulnerability in cable modems called Cablehaunt (https://cablehaunt.com/).

Would this affect Sonic modems?

If so, what are remediation plans?

Thanks!

jeremy.

Re: Cablehaunt vulnerability in Sonic modems?

Posted: Fri Jan 10, 2020 4:39 pm
by sysops
Cool vulnerability! Requires local network access to begin exploitation though (but this can sorta be accomplished through malicious Javascript on any website).

Sonic is not affected. From the Cablehaunt FAQ...

Q: Am I Affected?

A: Start by determining if you get internet through a cable modem, since only cable modems are affected...

Re: Cablehaunt vulnerability in Sonic modems?

Posted: Fri Jan 10, 2020 5:35 pm
by dane
Bingo. It’s an exploit of the spectrum analyzer software that is embedded in the cable modem, which I presume is for coax diagnostics.