Blog | G5 Cyber Security

Comcast Xfinity web flaws exposed customer data

US communications giant Comcast Xfinity has had to patch two web vulnerabilities after Buzzfeed News learned of the issues from researcher Ryan Stevenson. The first was found on the in-home authentication page through which customers can pay bills without the inconvenience of having to log in. The second issue, which builds on the first, was found in a sign-up page for Comcast authorised retailers. An attacker who knew your IP number could then insert it into their own web requests, and keep refreshing the identification page. Each time they refreshed, the list of home addresses returned would include your address plus three randomly chosen other addresses.”]

Source: https://nakedsecurity.sophos.com/2018/08/10/comcast-xfinity-web-flaws-exposed-customer-data/

Exit mobile version