CVE-2019-7391

ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zyxel:dsl-491hnu-b10b_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:dsl-491hnu-b10b:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:zyxel:dsl-491hnu-b1b_v2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:dsl-491hnu-b1b_v2:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:48

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/151550/Zyxel-VMG3312-B10B-DSL-491HNU-B1-V2-Cross-Site-Request-Forgery.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/151550/Zyxel-VMG3312-B10B-DSL-491HNU-B1-V2-Cross-Site-Request-Forgery.html - Exploit, Third Party Advisory, VDB Entry
References () https://twitter.com/h1_yusuf - Third Party Advisory () https://twitter.com/h1_yusuf - Third Party Advisory
References () https://www.exploit-db.com/exploits/46326/ - Exploit, VDB Entry, Third Party Advisory () https://www.exploit-db.com/exploits/46326/ - Exploit, Third Party Advisory, VDB Entry
References () https://www.owasp.org/index.php/Cross-Site_Request_Forgery_%28CSRF%29 - () https://www.owasp.org/index.php/Cross-Site_Request_Forgery_%28CSRF%29 -

07 Nov 2023, 03:13

Type Values Removed Values Added
References
  • {'url': 'https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)', 'name': 'https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)', 'tags': ['Technical Description', 'Third Party Advisory'], 'refsource': 'MISC'}
  • () https://www.owasp.org/index.php/Cross-Site_Request_Forgery_%28CSRF%29 -

Information

Published : 2019-03-21 16:01

Updated : 2024-11-21 04:48


NVD link : CVE-2019-7391

Mitre link : CVE-2019-7391

CVE.ORG link : CVE-2019-7391


JSON object : View

Products Affected

zyxel

  • dsl-491hnu-b10b
  • dsl-491hnu-b10b_firmware
  • dsl-491hnu-b1b_v2_firmware
  • dsl-491hnu-b1b_v2
CWE
CWE-352

Cross-Site Request Forgery (CSRF)