PT-2014-5504 · Beetel · Beetel 450Tc2 Router
Shyamkumar Somana
·
Published
2014-05-20
·
Updated
2014-05-21
·
CVE-2014-3792
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Beetel 450TC2 Router with firmware TX6-0Q-005 retail
Description
A cross-site request forgery (CSRF) issue allows remote attackers to hijack the authentication of administrators for requests that change the administrator password. This is achieved via the
uiViewTools Password and uiViewTools PasswordConfirm parameters to "Forms/tools admin 1".Recommendations
For Beetel 450TC2 Router with firmware TX6-0Q-005 retail, as a temporary workaround, consider restricting access to the "Forms/tools admin 1" endpoint until a patch is available. Avoid using the
uiViewTools Password and uiViewTools PasswordConfirm parameters in this endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Beetel 450Tc2 Router