PT-2014-5504 · Beetel · Beetel 450Tc2 Router

Shyamkumar Somana

·

Publicado

2014-05-20

·

Atualizado

2014-05-21

·

CVE-2014-3792

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Beetel 450TC2 Router with firmware TX6-0Q-005 retail
Description A cross-site request forgery (CSRF) issue allows remote attackers to hijack the authentication of administrators for requests that change the administrator password. This is achieved via the uiViewTools Password and uiViewTools PasswordConfirm parameters to "Forms/tools admin 1".
Recommendations For Beetel 450TC2 Router with firmware TX6-0Q-005 retail, as a temporary workaround, consider restricting access to the "Forms/tools admin 1" endpoint until a patch is available. Avoid using the uiViewTools Password and uiViewTools PasswordConfirm parameters in this endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3792

Produtos afetados

Beetel 450Tc2 Router