PT-2016-6777 · Huawei · Huawei Ws331A
Zixian
·
Published
2016-09-21
·
Updated
2016-09-22
·
CVE-2016-6158
CVSS v2.0
7.1
High
| Vector | AV:N/AC:H/Au:N/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Huawei WS331a versions prior to V100R001C01B112
Description
The issue affects Huawei WS331a routers, allowing remote attackers to hijack the authentication of administrators. This can be done through cross-site request forgery (CSRF) vulnerabilities for requests that restore factory settings or reboot the device.
Recommendations
For versions prior to V100R001C01B112, update to V100R001C01B112 or later to resolve the issue. As a temporary workaround, consider restricting access to the router's administrative interface to minimize the risk of exploitation.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Ws331A