← Vulnerability feed

Vulnerability record · CVE-2016-10372 · published 16 May 2017

CVE-2016-10372: Eir D1000 modem TR-064 access control flaw allows remote command execution

Eir · D1000 Modem Firmware

The Eir D1000 modem does not properly restrict the TR-064 protocol, letting remote attackers reach it over TCP port 7547. By opening WAN access to TCP port 80, retrieving the login password (which defaults to the Wi-Fi password), and abusing the NewNTPServer feature, an attacker can run arbitrary commands on the device.

9.8 CVSS 3.0 Critical EPSS 82% · top 0.4% CWE-264 · Permissions and access controls
9.8CVSS 3.0 base score, v2 10.0
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547, as demonstrated by opening WAN access to TCP port 80, retrieving the login password (which defaults to the Wi-Fi password), and using the NewNTPServer feature.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, public exploit references, and a very high EPSS score make this an urgent remote code execution risk.

What it is

The Eir D1000 modem does not properly restrict the TR-064 protocol, letting remote attackers reach it over TCP port 7547. By opening WAN access to TCP port 80, retrieving the login password (which defaults to the Wi-Fi password), and abusing the NewNTPServer feature, an attacker can run arbitrary commands on the device.

Impact

An attacker gains arbitrary command execution on the modem, giving full control of the device and its network position. Because the default login password equals the Wi-Fi password, compromise can also expose the local wireless network.

Attack surface

Reachable remotely over the network via TCP port 7547 (TR-064) with no authentication or user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The described chain also involves WAN access to TCP port 80 and the NewNTPServer feature.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.81474, 99.6th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.

What to do

  • Apply vendor firmware updates for the Eir D1000 modem if available; if no fix exists, replace or isolate the device.
  • Block inbound access to TCP port 7547 (and 80) from the WAN at the network edge.
  • Change the default login password and ensure it is not the same as the Wi-Fi password.
  • Disable remote/WAN management of the modem where the feature is not required.
  • Segment or retire affected modems that cannot be patched.

Detection

  • Monitor for inbound connections to TCP port 7547 and unexpected WAN access to TCP port 80 on modems.
  • Alert on TR-064 SOAP requests invoking the NewNTPServer action.
  • Watch for unexpected outbound traffic or command execution artifacts from modem management addresses.
  • Audit modem login events and password changes for signs of default-credential use.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-10372 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2016-10372), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.