First published: Mon Nov 06 2017(Updated: )
Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login screen using the default password of 123 and submit arbitrary requests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Grandstream Ht802 Firmware | ||
Grandstream Ht802 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2017-16565.
The severity of CVE-2017-16565 is high with a CVSS score of 8.8.
The affected software for CVE-2017-16565 is Grandstream Ht802 devices with firmware versions prior to the patched version.
CVE-2017-16565 allows attackers to authenticate a user via the login screen using the default password of 123 and submit arbitrary requests.
Yes, a fix for CVE-2017-16565 is available in the patched version of the firmware.