CVE-2013-0717

Multiple cross-site request forgery (CSRF) vulnerabilities in the web-based management utility on the NEC AtermWR9500N, AtermWR8600N, AtermWR8370N, AtermWR8160N, AtermWM3600R, and AtermWM3450RN routers allow remote attackers to hijack the authentication of administrators for requests that (1) initialize settings or (2) reboot the device.
Configurations

Configuration 1 (hide)

OR cpe:2.3:h:nec:atermwm3450rn:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:atermwm3600r:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:atermwr8160n:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:atermwr8370n:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:atermwr8600n:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:atermwr9500n:-:*:*:*:*:*:*:*

History

21 Nov 2024, 01:48

Type Values Removed Values Added
References () http://jpn.nec.com/security-info/secinfo/nv13-005.html - () http://jpn.nec.com/security-info/secinfo/nv13-005.html -
References () http://jvn.jp/en/jp/JVN59503133/6443/index.html - () http://jvn.jp/en/jp/JVN59503133/6443/index.html -
References () http://jvn.jp/en/jp/JVN59503133/index.html - () http://jvn.jp/en/jp/JVN59503133/index.html -
References () http://jvndb.jvn.jp/jvndb/JVNDB-2013-000024 - () http://jvndb.jvn.jp/jvndb/JVNDB-2013-000024 -

Information

Published : 2013-03-19 18:55

Updated : 2024-11-21 01:48


NVD link : CVE-2013-0717

Mitre link : CVE-2013-0717

CVE.ORG link : CVE-2013-0717


JSON object : View

Products Affected

nec

  • atermwm3600r
  • atermwr8600n
  • atermwr9500n
  • atermwr8370n
  • atermwr8160n
  • atermwm3450rn
CWE
CWE-352

Cross-Site Request Forgery (CSRF)