CVE-2013-3963: CSRF
Cross-site request forgery (CSRF) vulnerability in goform/usermanage in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WPHD, GXV3500, and possibly other camera models allows remote attackers to hijack the authentication of unspecified victims for requests that add users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3963?
CVE-2013-3963 has a medium severity rating due to its potential for cross-site request forgery attacks.
How do I fix CVE-2013-3963?
To fix CVE-2013-3963, update your Grandstream GXV device firmware to a version that addresses this vulnerability.
Which Grandstream camera models are affected by CVE-2013-3963?
CVE-2013-3963 affects several Grandstream camera models, including GXV3501, GXV3504, GXV3601, GXV3615W/P, and others.
What is cross-site request forgery as referenced in CVE-2013-3963?
Cross-site request forgery (CSRF) is a type of attack that tricks the user into executing unwanted actions on a web application in which they are authenticated.
Is it possible for attackers to exploit CVE-2013-3963 remotely?
Yes, attackers can exploit CVE-2013-3963 remotely to hijack user authentication without physical access to the device.