CVE-2016-1228: CSRF
Cross-site request forgery (CSRF) vulnerability on NTT EAST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1006 and earlier and NTT WEST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1005 and earlier allows remote attackers to hijack the authentication of arbitrary users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1228?
The severity of CVE-2016-1228 is classified as medium due to the potential for remote attackers to hijack user sessions.
How do I fix CVE-2016-1228?
To fix CVE-2016-1228, upgrade to the latest firmware versions for your NTT EAST or NTT WEST Hikari Denwa router.
Are all versions of NTT EAST Hikari Denwa routers vulnerable to CVE-2016-1228?
Not all versions are vulnerable; only those with firmware PR-400MI, RT-400MI, RV-440MI version 07.00.1006 and earlier are affected.
Are all versions of NTT WEST Hikari Denwa routers vulnerable to CVE-2016-1228?
Only NTT WEST Hikari Denwa routers with firmware versions PR-400MI, RT-400MI, RV-440MI version 07.00.1005 and earlier are vulnerable.
What type of vulnerability is CVE-2016-1228?
CVE-2016-1228 is a cross-site request forgery (CSRF) vulnerability that can allow attackers to perform unauthorized actions on behalf of users.