ID

VAR-201310-0651


TITLE

Multiple Cross-Site Request Forgery Vulnerabilities in UNICORN WB-3300NR Router

Trust: 0.6

sources: CNVD: CNVD-2013-14258

DESCRIPTION

UNICORN WB-3300NR Router Management Page has multiple cross-site request forgery vulnerabilities, allowing remote attackers to build malicious URIs, enticing users to resolve, and performing arbitrary operations in the target user context, such as resetting factory settings, changing DNS settings, and obtaining WPA passwords. UNICORN WB-3300NR Router is a wireless router product from UNICORN in Korea. A cross-site request forgery vulnerability exists in the UNICORN WB-3300NR Router, which originates from a program that does not properly filter HTTP requests. A remote attacker could use this vulnerability to perform unauthorized operations and take control of an affected device. This may aid in other attacks

Trust: 1.35

sources: CNVD: CNVD-2013-14258 // CNNVD: CNNVD-201311-012 // BID: 63465

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-14258

AFFECTED PRODUCTS

vendor:unicornmodel:co.,ltd wb-3300nr routerscope:eqversion:1.0

Trust: 0.6

vendor:unicornmodel:wb-3300nrscope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2013-14258 // BID: 63465

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2013-14258
value: LOW

Trust: 0.6

CNVD: CNVD-2013-14258
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2013-14258

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201311-012

TYPE

cross-site request forgery

Trust: 0.6

sources: CNNVD: CNNVD-201311-012

EXTERNAL IDS

db:BIDid:63465

Trust: 1.5

db:CNVDid:CNVD-2013-14258

Trust: 0.6

db:CNNVDid:CNNVD-201311-012

Trust: 0.6

sources: CNVD: CNVD-2013-14258 // BID: 63465 // CNNVD: CNNVD-201311-012

REFERENCES

url:http://seclists.org/bugtraq/2013/oct/158

Trust: 0.9

url:http://www.securityfocus.com/bid/63465

Trust: 0.6

url:http://www.eunicorn.co.kr/kimsboard7/_product.php?inc=wb-3300nr

Trust: 0.3

sources: CNVD: CNVD-2013-14258 // BID: 63465 // CNNVD: CNNVD-201311-012

CREDITS

jsibley1

Trust: 0.9

sources: BID: 63465 // CNNVD: CNNVD-201311-012

SOURCES

db:CNVDid:CNVD-2013-14258
db:BIDid:63465
db:CNNVDid:CNNVD-201311-012

LAST UPDATE DATE

2022-05-17T01:51:11.743000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-14258date:2013-11-05T00:00:00
db:BIDid:63465date:2013-10-30T00:00:00
db:CNNVDid:CNNVD-201311-012date:2013-11-04T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-14258date:2013-11-05T00:00:00
db:BIDid:63465date:2013-10-30T00:00:00
db:CNNVDid:CNNVD-201311-012date:2013-10-30T00:00:00