Cross-site request forgery (CSRF) vulnerability in multiple Century Systems routers including XR-410 before 1.6.9, XR-510 before 3.5.3, XR-440 before 1.7.8, and other XR series routers from XR-510 to XR-730 allows remote attackers to modify configuration as the administrator via unknown vectors.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/43949 | vdb entry |
http://www.centurysys.co.jp/support/xr_common/JVN67573833.html | vendor advisory |
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000042.html | third party advisory |
http://secunia.com/advisories/31173 | third party advisory |
http://jvn.jp/en/jp/JVN67573833/index.html | third party advisory |