CVE-2014-4155: CSRF
Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0aZRDLK allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a request to Forms/toolsadmin1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4155?
CVE-2014-4155 is considered a high severity vulnerability due to its potential to allow unauthorized administrative access.
How do I fix CVE-2014-4155?
To fix CVE-2014-4155, update the ZTE ZXV10 W300 router firmware to the latest version provided by ZTE.
What types of attacks can exploit CVE-2014-4155?
CVE-2014-4155 can be exploited through cross-site request forgery attacks that target admin password changes.
Who is affected by CVE-2014-4155?
Administrators using the ZTE ZXV10 W300 router with firmware version W300V1.0.0a_ZRD_LK are affected by CVE-2014-4155.
Is there a workaround for CVE-2014-4155?
A potential workaround for CVE-2014-4155 is to disable remote management features on the ZTE ZXV10 W300 router.