CVE-2012-4746: CSRF
Published Aug 31, 2012
·Updated
Cross-site request forgery (CSRF) vulnerability in accessaccount.cgi in ZTE ZXDSL 831IIV7.5.0aZ29OV allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter.
Affected Software
1 affected component
ZTE ZXDSL=831iiv7.5.0a_z29_ov
Event History
Aug 31, 2012
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4746?
CVE-2012-4746 has a medium severity level due to its potential to allow unauthorized administrator access.
2
How do I fix CVE-2012-4746?
To fix CVE-2012-4746, it is recommended to apply the latest firmware update provided by ZTE.
3
What type of vulnerability is CVE-2012-4746?
CVE-2012-4746 is a cross-site request forgery (CSRF) vulnerability.
4
Who is affected by CVE-2012-4746?
CVE-2012-4746 affects users of the ZTE ZXDSL 831IIV7.5.0a_Z29_OV model.
5
What can attackers do with CVE-2012-4746?
Attackers can use CVE-2012-4746 to hijack admin authentication and change the administrator password.