CVE-2008-0524
Summary
| CVE | CVE-2008-0524 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-01-31 20:00:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Cross-site request forgery (CSRF) vulnerability in the management interface in multiple Yamaha RT series routers allows remote attackers to change password settings and probably other configuration settings as administrators via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Yamaha | Rt107e | All | All | All | All |
| Hardware | Yamaha | Rt52pro | All | All | All | All |
| Hardware | Yamaha | Rt56v | All | All | All | All |
| Hardware | Yamaha | Rt57i | All | All | All | All |
| Hardware | Yamaha | Rt58i | All | All | All | All |
| Hardware | Yamaha | Rt60w | All | All | All | All |
| Hardware | Yamaha | Rt80i | All | All | All | All |
| Hardware | Yamaha | Rta50i | All | All | All | All |
| Hardware | Yamaha | Rta52i | All | All | All | All |
| Hardware | Yamaha | Rta54i | All | All | All | All |
| Hardware | Yamaha | Rta55i | All | All | All | All |
| Hardware | Yamaha | Rtv700 | All | All | All | All |
| Hardware | Yamaha | Rtw65b | All | All | All | All |
| Hardware | Yamaha | Rtw65i | All | All | All | All |
| Hardware | Yamaha | Rtx1000 | All | All | All | All |
| Hardware | Yamaha | Rtx1100 | All | All | All | All |
| Hardware | Yamaha | Rtx1500 | All | All | All | All |
| Hardware | Yamaha | Srt100 | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Yamaha RT Series Routers Cross-Site Request Forgery Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| JVN#88575577: 複数のヤマハルーター製品におけるクロスサイトリクエストフォージェリの脆弱性 | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| Yamaha RT Series Routers Cross-Site Request Forgery Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| FAQ for YAMAHA RT Series / Security | af854a3a-2127-422b-91ae-364da2661108 | www.rtpro.yamaha.co.jp | |
| JVN:JVN#88575577 | MITRE | jvn.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.