It doesn't seem to be feasible using this vulnerability:
> Cable Haunt is exploited in two steps. First, access to the vulnerable endpoint is gained through a client on the local network, such as a browser. (emphasis mine)
> Cable Haunt is exploited in two steps. First, access to the vulnerable endpoint is gained through a client on the local network, such as a browser. (emphasis mine)
This issue is based on WebSockets where the software on the modem:
a) Doesn't verify any of the origin headers sent, so any origin works (rebinding is designed to beat origin checks)
b) Copies an uploaded message straight onto the stack without doing any size checks
Edit: or you could get them to click on a link