Comtrend CT-5367 ADSL Router Cross-Site Request Forgery Vulnerability
BID:46741
Info
Comtrend CT-5367 ADSL Router Cross-Site Request Forgery Vulnerability
| Bugtraq ID: | 46741 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 04 2011 12:00AM |
| Updated: | Mar 04 2011 12:00AM |
| Credit: | Todor Donev |
| Vulnerable: |
Comtrend CT-5367 A111-312BTC-C01_R12 |
| Not Vulnerable: | |
Discussion
Comtrend CT-5367 ADSL Router Cross-Site Request Forgery Vulnerability
Comtrend CT-5367 ADSL router is prone to a cross-site request-forgery vulnerability.
Attackers can exploit this issue by tricking an unsuspecting user into visiting a malicious webpage. The page will consist of specially crafted script code designed to perform some action on the attacker's behalf.
Successful exploits can allow attackers to run privileged commands on the affected device.
Comtrend CT-5367 ADSL router is prone to a cross-site request-forgery vulnerability.
Attackers can exploit this issue by tricking an unsuspecting user into visiting a malicious webpage. The page will consist of specially crafted script code designed to perform some action on the attacker's behalf.
Successful exploits can allow attackers to run privileged commands on the affected device.
Exploit / POC
Comtrend CT-5367 ADSL Router Cross-Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Comtrend CT-5367 ADSL Router Cross-Site Request Forgery Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Comtrend CT-5367 ADSL Router Cross-Site Request Forgery Vulnerability
References:
References:
- Vendor Homepage (Comtrend)