First published: Thu Sep 10 2009(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in the web management interface in the ZyXEL P-330W router allow remote attackers to hijack the authentication of administrators for requests that (1) enable remote router management via goform/formRmtMgt or (2) modify the administrator password via goform/formPasswordSetup.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZyXEL P-330W router |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6730 is considered a high severity vulnerability due to its potential to allow remote attackers to hijack administrator sessions.
To fix CVE-2007-6730, it is recommended to disable remote management on the ZyXEL P-330W router and apply any available firmware updates.
CVE-2007-6730 affects users of the ZyXEL P-330W router with its web management interface enabled.
CVE-2007-6730 allows attackers to perform cross-site request forgery (CSRF) attacks that can change administrative settings.
While CVE-2007-6730 was discovered in 2007, older devices like the ZyXEL P-330W can still be in use and thus remain a relevant concern for security.