First published: Tue Mar 06 2018(Updated: )
Cross-site request forgery (CSRF) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allows remote attackers to hijack the authentication of unspecified users for requests that enable SNMP on the remote device via vectors involving goform/setSnmp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Draytek Vigorap 910c Firmware | =1.2.0-rc3 | |
Draytek Vigorap 910c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue is CVE-2017-11649.
CVE-2017-11649 has a severity score of 8.8, indicating a high severity level.
The affected software for CVE-2017-11649 is DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594.
CVE-2017-11649 allows remote attackers to hijack the authentication of unspecified users for requests that enable SNMP on the remote device.
To fix CVE-2017-11649, it is recommended to update the firmware of DrayTek Vigor AP910C devices to a version that addresses the CSRF vulnerability.