CVE-2017-12589

ToMAX R60G R60GV2-V2.0-v.2.6.3-170330 devices do not have any protection against a CSRF attack.
References
Link Resource
http://www.securityfocus.com/bid/100438 Third Party Advisory VDB Entry
https://iscouncil.blogspot.com/2017/08/cross-site-request-forgery_11.html Exploit Technical Description
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tomaxcom:r60g_firmware:2.6.3-170330:*:*:*:*:*:*:*
cpe:2.3:h:tomaxcom:r60g:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tomaxcom:r60gv2_firmware:2.6.3-170330:*:*:*:*:*:*:*
cpe:2.3:h:tomaxcom:r60gv2:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-08-18 17:29

Updated : 2024-02-28 16:04


NVD link : CVE-2017-12589

Mitre link : CVE-2017-12589

CVE.ORG link : CVE-2017-12589


JSON object : View

Products Affected

tomaxcom

  • r60g_firmware
  • r60g
  • r60gv2
  • r60gv2_firmware
CWE
CWE-352

Cross-Site Request Forgery (CSRF)