Cox Communications fixed an authorization bypass vulnerability that could have enabled threat actors to abuse backend APIs to reset millions of modems and steal customer data.
Discovered by Sam Curry, the exploit gave a similar set of permissions as the ISP tech support.