CVE-2014-9027: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in ZTE ZXDSL 831CII allow remote attackers to hijack the authentication of administrators for requests that disable modem lan ports via the (1) enblftp, (2) enblhttp, (3) enblsnmp, (4) enbltelnet, (5) enbltftp, (6) enblicmp, or (7) enblssh parameter to accesslocal.cmd.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9027?
CVE-2014-9027 is considered to have a medium severity level due to the risk of remote authentication hijacking for modem administration.
How do I fix CVE-2014-9027?
To fix CVE-2014-9027, update the ZTE ZXDSL 831CII firmware to the latest version that addresses the CSRF vulnerabilities.
What types of attacks are possible with CVE-2014-9027?
CVE-2014-9027 allows attackers to exploit CSRF vulnerabilities to disable modem LAN ports and manipulate device settings.
Who is affected by CVE-2014-9027?
CVE-2014-9027 affects users of the ZTE ZXDSL 831CII modem firmware specifically.
Is there a patch available for CVE-2014-9027?
Yes, ZTE provides patches in their firmware updates that resolve the vulnerabilities associated with CVE-2014-9027.