CVE-2014-5437: XSS
Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) enable remote management via a request to remotemanagement.php, (2) add a port forwarding rule via a request to portforwardingadd.php, (3) change the wireless network to open via a request to wirelessnetworkconfigurationedit.php, or (4) conduct cross-site scripting (XSS) attacks via the keyword parameter to managedsitesaddkeyword.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5437?
CVE-2014-5437 is considered a medium severity vulnerability due to its potential to allow remote attackers to hijack administrative sessions.
How do I fix CVE-2014-5437?
To fix CVE-2014-5437, upgrade the Arris Touchstone TG862G/CT firmware to a version later than 7.6.59S.CT.
What is the impact of CVE-2014-5437?
The impact of CVE-2014-5437 includes unauthorized remote access and control over the device's management features.
Who is affected by CVE-2014-5437?
Users of the Arris Touchstone TG862G/CT Telephony Gateway running firmware 7.6.59S.CT and earlier are affected by CVE-2014-5437.
What type of vulnerability is CVE-2014-5437?
CVE-2014-5437 is a cross-site request forgery (CSRF) vulnerability that allows attackers to exploit user sessions.