CVE-2017-12589

ToMAX R60G R60GV2-V2.0-v.2.6.3-170330 devices do not have any protection against a CSRF attack.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tomaxcom:r60g_firmware:2.6.3-170330:*:*:*:*:*:*:*
cpe:2.3:h:tomaxcom:r60g:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tomaxcom:r60gv2_firmware:2.6.3-170330:*:*:*:*:*:*:*
cpe:2.3:h:tomaxcom:r60gv2:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:09

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/100438 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/100438 - Third Party Advisory, VDB Entry
References () https://iscouncil.blogspot.com/2017/08/cross-site-request-forgery_11.html - Exploit, Technical Description () https://iscouncil.blogspot.com/2017/08/cross-site-request-forgery_11.html - Exploit, Technical Description

Information

Published : 2017-08-18 17:29

Updated : 2024-11-21 03:09


NVD link : CVE-2017-12589

Mitre link : CVE-2017-12589

CVE.ORG link : CVE-2017-12589


JSON object : View

Products Affected

tomaxcom

  • r60gv2
  • r60gv2_firmware
  • r60g_firmware
  • r60g
CWE
CWE-352

Cross-Site Request Forgery (CSRF)