First published: Mon May 22 2017(Updated: )
Cross-site request forgery (CSRF) vulnerability in L-04D firmware version V10a and V10b allows remote attackers to hijack the authentication of administrators to perform arbitrary operations via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Nttdocomo L-04D | =v10a | |
Nttdocomo L-04D | =v10b | |
LG L-04D |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4854 is classified as a high severity vulnerability due to its potential to allow remote attackers to hijack administrative authentication.
To fix CVE-2016-4854, update the L-04D firmware to a version that is not affected by the vulnerability.
CVE-2016-4854 allows attackers to perform cross-site request forgery (CSRF) attacks to execute arbitrary operations as an administrator.
CVE-2016-4854 affects L-04D firmware versions V10a and V10b.
Administrators using vulnerable versions of the L-04D firmware are at risk from CVE-2016-4854.