ID

VAR-201301-0216


CVE

CVE-2012-1922


TITLE

Sitecom WLM-2501 Vulnerable to cross-site request forgery

Trust: 0.8

sources: JVNDB: JVNDB-2013-001239

DESCRIPTION

Multiple cross-site request forgery (CSRF) vulnerabilities in Sitecom WLM-2501 allow remote attackers to hijack the authentication of administrators for requests that modify settings for (1) Mac Filtering via admin/formFilter, (2) IP/Port Filtering via formFilter, (3) Port Forwarding via formPortFw, (4) Wireless Access Control via admin/formWlAc, (5) Wi-Fi Protected Setup via formWsc, (6) URL Blocking Filter via formURL, (7) Domain Blocking Filter via formDOMAINBLK, and (8) IP Address ACL Filter via admin/formACL in goform/, different vectors than CVE-2012-1921. Sitecom WLM-2501 Contains a cross-site request forgery vulnerability. The Sitecom WLM-2501 is a router device. Sitecom WLM-2501 has multiple CSRF vulnerabilities. Attackers build malicious URIs, entice users to resolve, perform administrator actions in the target user context, and change router parameters

Trust: 2.16

sources: NVD: CVE-2012-1922 // JVNDB: JVNDB-2013-001239 // CNVD: CNVD-2013-00535

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

category:['network device']sub_category:router

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2013-00535

AFFECTED PRODUCTS

vendor:sitecommodel:wlm-2501scope:eqversion: -

Trust: 1.6

vendor:sitecommodel:wlm-2501scope: - version: -

Trust: 0.8

vendor:sitecommodel:wlm-2501scope:eqversion:0

Trust: 0.6

sources: CNVD: CNVD-2013-00535 // JVNDB: JVNDB-2013-001239 // CNNVD: CNNVD-201301-477 // NVD: CVE-2012-1922

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2012-1922
value: MEDIUM

Trust: 1.0

NVD: CVE-2012-1922
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201301-477
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2012-1922
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

sources: JVNDB: JVNDB-2013-001239 // CNNVD: CNNVD-201301-477 // NVD: CVE-2012-1922

PROBLEMTYPE DATA

problemtype:CWE-352

Trust: 1.8

sources: JVNDB: JVNDB-2013-001239 // NVD: CVE-2012-1922

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201301-477

TYPE

cross-site request forgery

Trust: 0.6

sources: CNNVD: CNNVD-201301-477

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-001239

PATCH

title:Wireless Modem Router 300N WLM-2501url:http://www.sitecom.com/wireless-modem-router-300n/p/859

Trust: 0.8

sources: JVNDB: JVNDB-2013-001239

EXTERNAL IDS

db:NVDid:CVE-2012-1922

Trust: 3.1

db:JVNDBid:JVNDB-2013-001239

Trust: 0.8

db:CNVDid:CNVD-2013-00535

Trust: 0.6

db:CNNVDid:CNNVD-201301-477

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2013-00535 // JVNDB: JVNDB-2013-001239 // CNNVD: CNNVD-201301-477 // NVD: CVE-2012-1922

REFERENCES

url:http://www.webapp-security.com/wp-content/uploads/2012/03/sitecom-wlm-2501-new-multiple-csrf-vulnerabilities-1.txt

Trust: 1.6

url:http://www.webapp-security.com/2012/03/sitecom-wlm-2501-multiple-csrf-vulnerabilities

Trust: 1.6

url:http://www.webapp-security.com/2012/03/sitecom-wlm-2501-multiple-csrf-vulnerabilities/

Trust: 1.4

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-1922

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2012-1922

Trust: 0.8

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2013-00535 // JVNDB: JVNDB-2013-001239 // CNNVD: CNNVD-201301-477 // NVD: CVE-2012-1922

SOURCES

db:OTHERid: -
db:CNVDid:CNVD-2013-00535
db:JVNDBid:JVNDB-2013-001239
db:CNNVDid:CNNVD-201301-477
db:NVDid:CVE-2012-1922

LAST UPDATE DATE

2025-04-11T22:12:02.010000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-00535date:2013-05-27T00:00:00
db:JVNDBid:JVNDB-2013-001239date:2013-01-25T00:00:00
db:CNNVDid:CNNVD-201301-477date:2013-01-25T00:00:00
db:NVDid:CVE-2012-1922date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-00535date:2013-01-25T00:00:00
db:JVNDBid:JVNDB-2013-001239date:2013-01-25T00:00:00
db:CNNVDid:CNNVD-201301-477date:2013-01-24T00:00:00
db:NVDid:CVE-2012-1922date:2013-01-24T01:55:02.223