CVE-2013-3098
TRENDnet TEW-812DRU - Cross-Site Request Forgery/Command Injection Root
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
Multiple cross-site request forgery (CSRF) vulnerabilities in TRENDnet TEW-812DRU router with firmware before 1.0.9.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change admin credentials in a request to setSysAdm.cgi, (2) enable remote management or (3) enable port forwarding in an Apply action to uapply.cgi, or (4) have unspecified impact via a request to setNTP.cgi. NOTE: some of these details are obtained from third party information.
Múltiples vulnerabilidades de CSRF en el router TRENDnet TEW-812DRU con firmware anterior a 1.0.9.0 permite a atacantes remotos secuestrar la autenticación de administradores para solicitudes que (1) cambian las credenciales de admin en una solicitud hacia setSysAdm.cgi, (2) habilitan la gestión remota o (3) habilitan el reenvío de puertos en una acción Apply hacia uapply.cgi, o (4) tienen un impacto no especificado a través de una solicitud hacia setNTP.cgi. NOTA: algunos de estos detalles se obtienen de información de terceras partes.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-04-17 CVE Reserved
- 2013-07-28 First Exploit
- 2014-02-04 CVE Published
- 2024-02-03 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://osvdb.org/95803 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/54310 | 2014-02-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trendnet Search vendor "Trendnet" | Tew-812dru Firmware Search vendor "Trendnet" for product "Tew-812dru Firmware" | 1.0.8.0 Search vendor "Trendnet" for product "Tew-812dru Firmware" and version "1.0.8.0" | - |
Affected
| in | Trendnet Search vendor "Trendnet" | Tew-812dru Search vendor "Trendnet" for product "Tew-812dru" | - | - |
Affected
|