PT-2016-6777 · Huawei · Huawei Ws331A
Zixian
·
Publicado
2016-09-21
·
Atualizado
2016-09-22
·
CVE-2016-6158
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:H/Au:N/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Huawei WS331a versions prior to V100R001C01B112
Description
The issue affects Huawei WS331a routers, allowing remote attackers to hijack the authentication of administrators. This can be done through cross-site request forgery (CSRF) vulnerabilities for requests that restore factory settings or reboot the device.
Recommendations
For versions prior to V100R001C01B112, update to V100R001C01B112 or later to resolve the issue. As a temporary workaround, consider restricting access to the router's administrative interface to minimize the risk of exploitation.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Huawei Ws331A