CVE-2014-3792: CSRF
Cross-site request forgery (CSRF) vulnerability in Beetel 450TC2 Router with firmware TX6-0Q-005retail allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the uiViewToolsPassword and uiViewToolsPasswordConfirm parameters to Forms/toolsadmin1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3792?
CVE-2014-3792 is classified as a high severity vulnerability due to its potential to allow remote attackers to hijack administrator sessions.
How do I fix CVE-2014-3792?
To mitigate CVE-2014-3792, it is recommended to update the Beetel 450TC2 Router to the latest firmware that addresses this vulnerability.
Who is affected by CVE-2014-3792?
CVE-2014-3792 affects users of the Beetel 450TC2 Router running firmware version TX6-0Q-005_retail.
What type of vulnerability is CVE-2014-3792?
CVE-2014-3792 is a cross-site request forgery (CSRF) vulnerability.
What can attackers do with CVE-2014-3792?
Attackers exploiting CVE-2014-3792 can change the administrator password without authorization.