// For flags

CVE-2013-0126

Verizon Fios Router MI424WR-GEN3I - Cross-Site Request Forgery

Severity Score

8.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I router with firmware 40.19.36 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrative accounts via the username and user_level parameters or (2) enable remote administration via the is_telnet_primary and is_telnet_secondary parameters.

Múltiples vulnerabilidades de falsificación de petición en sitios cruzados (CSRF) en index.cgi en el router Verizon FIOS Actiontec MI424WR-GEN3I que permite a atacantes remotos secuestrar la autenticación de los administradores para peticiones que (1) agregan cuentas administrativas a través del nombre de usuario y parámetros user_level o (2) que permiten la administración remota a través de los parámetros is_telnet_primary y is_telnet_secondary.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-12-06 CVE Reserved
  • 2013-03-19 First Exploit
  • 2013-03-21 CVE Published
  • 2024-09-17 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Verizon
Search vendor "Verizon"
Fios Actiontec Mi424wr-gen31 Router Firmware
Search vendor "Verizon" for product "Fios Actiontec Mi424wr-gen31 Router Firmware"
40.19.36
Search vendor "Verizon" for product "Fios Actiontec Mi424wr-gen31 Router Firmware" and version "40.19.36"
-
Affected
in Verizon
Search vendor "Verizon"
Fios Actiontec Mi424wr-gen31 Router
Search vendor "Verizon" for product "Fios Actiontec Mi424wr-gen31 Router"
--
Affected