The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2018/Jan/28 | Mailing List Third Party Advisory |
https://www.exploit-db.com/exploits/43460/ | Exploit Third Party Advisory VDB Entry |
http://seclists.org/fulldisclosure/2018/Jan/28 | Mailing List Third Party Advisory |
https://www.exploit-db.com/exploits/43460/ | Exploit Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 03:17
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2018/Jan/28 - Mailing List, Third Party Advisory | |
References | () https://www.exploit-db.com/exploits/43460/ - Exploit, Third Party Advisory, VDB Entry |
Information
Published : 2018-01-12 17:29
Updated : 2024-11-21 03:17
NVD link : CVE-2017-16886
Mitre link : CVE-2017-16886
CVE.ORG link : CVE-2017-16886
JSON object : View
Products Affected
fiberhome
- lm53q1
- lm53q1_firmware
CWE
CWE-352
Cross-Site Request Forgery (CSRF)