PT-2013-2113 · Actiontec · Actiontec Mi424Wr-Gen3I

Jacob Holcomb

·

Publicado

2013-03-21

·

Atualizado

2013-10-07

·

CVE-2013-0126

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Actiontec MI424WR-GEN3I router with firmware 40.19.36
Description The issue concerns multiple cross-site request forgery (CSRF) vulnerabilities in the index.cgi file of the affected router. These vulnerabilities allow remote attackers to hijack the authentication of administrators for specific requests. The requests in question include adding administrative accounts via the username and user level parameters, as well as enabling remote administration through the is telnet primary and is telnet secondary parameters.
Recommendations For the Actiontec MI424WR-GEN3I router with firmware 40.19.36, consider disabling remote administration until a patch is available to prevent exploitation of the CSRF vulnerabilities. Additionally, restrict access to the index.cgi file and its associated parameters (username, user level, is telnet primary, and is telnet secondary) to minimize the risk of unauthorized administrative account additions or changes to remote administration settings.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-0126

Produtos afetados

Actiontec Mi424Wr-Gen3I