Network Security

Vulnerabilities Exposed Millions of Cox Modems to Remote Hacking

Cox recently patched a series of vulnerabilities that could have allowed hackers to remotely take control of millions of modems.

Modem hacked

Telecoms giant Cox Communications recently patched a series of vulnerabilities that could have allowed hackers to remotely take control of millions of modems used by the company’s customers, according to a researcher.

The vulnerabilities were discovered and responsibly reported to Cox in early March by Sam Curry, a reputable researcher who previously uncovered serious security flaws in products from Apple, airline and hotel rewards platform Points.com, and vehicles from over a dozen car makers

Curry started looking into the security of Cox modems in 2021, after his home modem was hacked. At the time, the telecoms firm replaced his compromised device with a new one before he was able to conduct a detailed analysis, but he took a closer look at Cox modems and systems in early 2024. 

His recent analysis led to the discovery of an API for which authorization could be bypassed, potentially enabling an unauthenticated attacker to gain the same privileges as Cox’s tech support team. Specifically, an attacker could abuse this API to overwrite configuration settings, access the router, and execute commands on the device. 

“This series of vulnerabilities demonstrated a way in which a fully external attacker with no prerequisites could’ve executed commands and modified the settings of millions of modems, accessed any business customer’s PII, and gained essentially the same permissions of an ISP support team,” the researcher explained in a blog post detailing his work

In a theoretical attack scenario described by Curry, an attacker could have searched for a targeted Cox business user through the exposed API using the target’s name, email address, phone number, or account number. 

Advertisement. Scroll to continue reading.

The attacker could then obtain additional information from the targeted user’s account, obtain their Wi-Fi password, and execute arbitrary commands, update device settings, or take over accounts.

Cox was informed about the vulnerabilities on March 4 and took action to prevent exploitation by the next day. The company also told Curry that it was conducting a comprehensive security review following his report. 

The vendor told the researcher that it had found no evidence of the vulnerability being exploited in the wild for malicious purposes.  

Related: Cinterion Modem Flaws Pose Risk to Millions of Devices in Industrial, Other Sectors

Related: Mysterious Threat Actor Used Chalubo Malware to Brick 600,000 Routers

Related: ‘5Ghoul’ Vulnerabilities Haunt Qualcomm, MediaTek 5G Modems

Related: Cuttlefish Malware Targets Routers, Harvests Cloud Authentication Data 

Related Content

Vulnerabilities

The updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks.

Email Security

An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges.

Nation-State

The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely.

Vulnerabilities

The vulnerabilities can allow attackers to bypass authentication and elevate their privileges to administrator.

Vulnerabilities

The flaw allows attackers to send files and execute them without authorization through an active remote session.

Vulnerabilities

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.

Vulnerabilities

Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.

Vulnerabilities

A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version