ID

VAR-E-201510-0188


TITLE

Multiple Routers Clickjacking Vulnerability

Trust: 0.3

sources: BID: 77386

DESCRIPTION

Multiple Routers are prone to a clickjacking vulnerability because it fails to perform validity checks on certain user actions through HTTP requests.
Successful exploits will allow an attacker to compromise the affected device or obtain sensitive information. Other attacks are also possible.

Trust: 0.3

sources: BID: 77386

AFFECTED PRODUCTS

vendor:yamahamodel:srt100scope:eqversion:0

Trust: 0.3

vendor:yamahamodel:rtx810scope:eqversion:11.1.21

Trust: 0.3

vendor:yamahamodel:rtx1500scope: - version: -

Trust: 0.3

vendor:yamahamodel:rtx1210scope:eqversion:0

Trust: 0.3

vendor:yamahamodel:rtx1200scope:eqversion:10.1.59

Trust: 0.3

vendor:yamahamodel:rtv01scope:eqversion:0

Trust: 0.3

vendor:yamahamodel:rt58iscope:eqversion:0

Trust: 0.3

vendor:yamahamodel:rt107escope:eqversion:0

Trust: 0.3

vendor:yamahamodel:nvr500scope:eqversion:11.0.25

Trust: 0.3

vendor:yamahamodel:fwx120scope:eqversion:11.3.8

Trust: 0.3

vendor:necmodel:infocagescope:eqversion:3.1

Trust: 0.3

vendor:yamahamodel:rtx810scope:neversion:11.1.25

Trust: 0.3

vendor:yamahamodel:rtx1200scope:neversion:10.1.65

Trust: 0.3

vendor:yamahamodel:nvr500scope:neversion:11.0.28

Trust: 0.3

vendor:yamahamodel:fwx120scope:neversion:11.3.13

Trust: 0.3

vendor:necmodel:infocagescope:neversion:5.1

Trust: 0.3

sources: BID: 77386

EXPLOIT

An attacker can exploit this issue by enticing an unsuspecting user to visit a crafted webpage.

Trust: 0.3

sources: BID: 77386

PRICE

Free

Trust: 0.3

sources: BID: 77386

TYPE

Design Error

Trust: 0.3

sources: BID: 77386

CREDITS

Noriaki Iwasaki of Cyber Defense Institute

Trust: 0.3

sources: BID: 77386

EXTERNAL IDS

db:JVNid:JVN48135658

Trust: 0.3

db:BIDid:77386

Trust: 0.3

sources: BID: 77386

REFERENCES

url:http://jvn.jp/en/jp/jvn48135658/index.html

Trust: 0.3

url:http://www.rtpro.yamaha.co.jp/rt/faq/security/jvn48135658.html

Trust: 0.3

url:http://jpn.nec.com/security-info/secinfo/nv15-019.html

Trust: 0.3

sources: BID: 77386

SOURCES

db:BIDid:77386

LAST UPDATE DATE

2022-07-27T09:29:57.661000+00:00


SOURCES UPDATE DATE

db:BIDid:77386date:2015-10-30T00:00:00

SOURCES RELEASE DATE

db:BIDid:77386date:2015-10-30T00:00:00