PT-2009-1177 · Zyxel · Zyxel P-330W
Santa Clause
·
Published
2009-09-10
·
Updated
2009-09-15
·
CVE-2007-6730
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ZyXEL P-330W router (affected versions not specified)
Description
The issue concerns multiple cross-site request forgery (CSRF) vulnerabilities in the web management interface. These vulnerabilities allow remote attackers to hijack the authentication of administrators for specific requests, including enabling remote router management via "goform/formRmtMgt" and modifying the administrator password via "goform/formPasswordSetup".
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zyxel P-330W