CVE-2017-16886
Summary
| CVE | CVE-2017-16886 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-12 17:29:00 UTC |
| Updated | 2018-02-02 14:27:00 UTC |
| Description | The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Fiberhome | Lm53q1 | - | All | All | All |
| Hardware | Fiberhome | Lm53q1 | - | All | All | All |
| Operating System | Fiberhome | Lm53q1 Firmware | vh519r05c01s38 | All | All | All |
| Operating System | Fiberhome | Lm53q1 Firmware | vh519r05c01s38 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| FiberHome LM53Q1 - Multiple Vulnerabilities - Hardware webapps Exploit | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| Full Disclosure: FiberHome MIFI LM53Q1 Multiple Vulnerabilities | FULLDISC | seclists.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.