CVE-2017-9490: CSRF
The Comcast firmware on Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG16822.2p7s2PRODsey) devices allows configuration changes via CSRF.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9490?
CVE-2017-9490 is classified as a moderate severity vulnerability due to its potential for unauthorized configuration changes.
How do I fix CVE-2017-9490?
To mitigate CVE-2017-9490, update the Arris TG1682G firmware to the latest version that addresses this CSRF vulnerability.
What devices are affected by CVE-2017-9490?
CVE-2017-9490 affects the Arris TG1682G device running firmware version 10.0.132.SIP.PC20.CT and TG1682_2.2p7s2_PROD_sey.
Is CVE-2017-9490 a CSRF vulnerability?
Yes, CVE-2017-9490 is a Cross-Site Request Forgery (CSRF) vulnerability that allows unauthorized configuration changes.
Can I prevent CVE-2017-9490 from being exploited?
Implementing strict access controls and ensuring the device firmware is up-to-date can help prevent the exploitation of CVE-2017-9490.