First published: Tue Mar 19 2013(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in the web-based management utility on the NEC AtermWR9500N, AtermWR8600N, AtermWR8370N, AtermWR8160N, AtermWM3600R, and AtermWM3450RN routers allow remote attackers to hijack the authentication of administrators for requests that (1) initialize settings or (2) reboot the device.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
NEC Aterm WM3450RN | ||
NEC Aterm WM3600R | ||
NEC Aterm WR8160N | ||
NEC Aterm WR8370N | ||
NEC Aterm WR8600N | ||
NEC Aterm WR9500N firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0717 is classified with a medium severity rating due to the potential for unauthorized access.
To mitigate CVE-2013-0717, users should implement CSRF protections within their application and ensure that all administrative sessions are secured.
CVE-2013-0717 affects multiple models of NEC Aterm routers including the WR9500N, WR8600N, WR8370N, WR8160N, WM3600R, and WM3450RN.
Yes, NEC released updates to address the vulnerabilities identified in CVE-2013-0717.
CVE-2013-0717 is classified as a cross-site request forgery (CSRF) vulnerability.