CVE-2014-5395
published 2014-11-21CVE-2014-5395: Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before…
PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EXPLOIT
EPSS
0.92%
55.8th percentile
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote attackers to hijack the authentication of users for requests that (1) modify configurations, (2) send SMS messages, or have other unspecified impact via unknown vectors.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | e3236_firmware | <= webui-13.100.10.00.03 | — |
| huawei | e3236_firmware | <= e3236s-2tcpu-22.146.29.00.00 | — |
| huawei | e3276_firmware | <= webui-13.100.09.00.03 | — |
| huawei | e3276_firmware | <= e3276s-150tcpu-22.265.03.00.00 | — |
| huawei | e5180s-22_firmware | <= e5180s-22tcpu-21.270.05.01.00 | — |
| huawei | e586bs-2_firmware | <= e586bs-2tcpu-21.322.08.00.889 | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-360246.htmhttp://www.securityfocus.com/bid/69162https://www.exploit-db.com/exploits/46092/http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-360246.htmhttp://www.securityfocus.com/bid/69162https://www.exploit-db.com/exploits/46092/
2014-11-21
Published