Cross-site request forgery (CSRF) vulnerability in the management interface in multiple Yamaha RT series routers allows remote attackers to change password settings and probably other configuration settings as administrators via unspecified vectors.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://www.rtpro.yamaha.co.jp/RT/FAQ/Security/JVN88575577.html | |
http://secunia.com/advisories/28690 | third party advisory |
http://www.securityfocus.com/bid/27491 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/40015 | vdb entry |
http://jvn.jp/jp/JVN%2388575577/index.html | third party advisory |