Vulnerability is due to a processing error in the role-based access control (RBAC) of URLs. An attacker could exploit this vulnerability by sending API commands via HTTP to a particular URL without prior authentication. The bug is designated CVE-2017-3791 and CWE-287. There are no workarounds or mitigations for the bug, Cisco is recommending that administrators install the update as soon as possible. It uses Broadband Forums TR-069 suite of protocols to provision and manage in-home devices.”]

