CVE-2017-16565: CSRF
Published Nov 6, 2017
·Updated
Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login screen using the default password of 123 and submit arbitrary requests.
Affected Software
2 affected components
Grandstream Ht802 Firmware
Grandstream HT802
Event History
Nov 6, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-16565.
2
What is the severity of CVE-2017-16565?
The severity of CVE-2017-16565 is high with a CVSS score of 8.8.
3
What is the affected software for CVE-2017-16565?
The affected software for CVE-2017-16565 is Grandstream Ht802 devices with firmware versions prior to the patched version.
4
How does CVE-2017-16565 work?
CVE-2017-16565 allows attackers to authenticate a user via the login screen using the default password of 123 and submit arbitrary requests.
5
Is there a fix available for CVE-2017-16565?
Yes, a fix for CVE-2017-16565 is available in the patched version of the firmware.