Vulnerability record · CVE-2016-10372 · published 16 May 2017
CVE-2016-10372: Eir D1000 modem TR-064 access control flaw allows remote command execution
Eir · D1000 Modem Firmware
The Eir D1000 modem does not properly restrict the TR-064 protocol, letting remote attackers reach it over TCP port 7547. By opening WAN access to TCP port 80, retrieving the login password (which defaults to the Wi-Fi password), and abusing the NewNTPServer feature, an attacker can run arbitrary commands on the device.
Description
The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547, as demonstrated by opening WAN access to TCP port 80, retrieving the login password (which defaults to the Wi-Fi password), and using the NewNTPServer feature.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, public exploit references, and a very high EPSS score make this an urgent remote code execution risk.
What it is
The Eir D1000 modem does not properly restrict the TR-064 protocol, letting remote attackers reach it over TCP port 7547. By opening WAN access to TCP port 80, retrieving the login password (which defaults to the Wi-Fi password), and abusing the NewNTPServer feature, an attacker can run arbitrary commands on the device.
Impact
An attacker gains arbitrary command execution on the modem, giving full control of the device and its network position. Because the default login password equals the Wi-Fi password, compromise can also expose the local wireless network.
Attack surface
Reachable remotely over the network via TCP port 7547 (TR-064) with no authentication or user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The described chain also involves WAN access to TCP port 80 and the NewNTPServer feature.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.81474, 99.6th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.
What to do
- Apply vendor firmware updates for the Eir D1000 modem if available; if no fix exists, replace or isolate the device.
- Block inbound access to TCP port 7547 (and 80) from the WAN at the network edge.
- Change the default login password and ensure it is not the same as the Wi-Fi password.
- Disable remote/WAN management of the modem where the feature is not required.
- Segment or retire affected modems that cannot be patched.
Detection
- Monitor for inbound connections to TCP port 7547 and unexpected WAN access to TCP port 80 on modems.
- Alert on TR-064 SOAP requests invoking the NewNTPServer action.
- Watch for unexpected outbound traffic or command execution artifacts from modem management addresses.
- Audit modem login events and password changes for signs of default-credential use.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://devicereversing.wordpress.com/2016/11/07/eirs-d1000-modem-is-wide-open-to-being-hacked/ | ExploitThird Party Advisory |
| https://ghostbin.com/paste/q2vq2 | |
| https://isc.sans.edu/forums/diary/TR069+NewNTPServer+Exploits+What+we+know+so+far/21763/ | ExploitTechnical DescriptionThird Party Advisory |
| https://devicereversing.wordpress.com/2016/11/07/eirs-d1000-modem-is-wide-open-to-being-hacked/ | ExploitThird Party Advisory |
| https://ghostbin.com/paste/q2vq2 | |
| https://isc.sans.edu/forums/diary/TR069+NewNTPServer+Exploits+What+we+know+so+far/21763/ | ExploitTechnical DescriptionThird Party Advisory |
Track CVE-2016-10372 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-10372), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.