ID

VAR-201311-0488


TITLE

Multiple Cross-Site Request Forgery Vulnerabilities in ADB Discus DRG A125G

Trust: 0.6

sources: CNVD: CNVD-2013-14742

DESCRIPTION

ADB Discus DRG A125G wlbasic.wl and wladv.wl have cross-site request forgery vulnerabilities that allow remote attackers to build malicious URIs, entice users to resolve, and perform malicious operations in the target user context. Discus DRG A125G is a wireless router product from Swiss ADB company. Cross-site request forgery vulnerability exists in ADB Discus DRG A125G router. A remote attacker could use this vulnerability to perform unauthorized operations and take control of an affected device

Trust: 1.35

sources: CNVD: CNVD-2013-14742 // CNNVD: CNNVD-201311-438 // BID: 63907

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-14742

AFFECTED PRODUCTS

vendor:adbmodel:discus drg a125gscope: - version: -

Trust: 0.9

sources: CNVD: CNVD-2013-14742 // BID: 63907

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2013-14742
value: LOW

Trust: 0.6

CNVD: CNVD-2013-14742
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2013-14742

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201311-438

TYPE

cross-site request forgery

Trust: 0.6

sources: CNNVD: CNNVD-201311-438

EXTERNAL IDS

db:BIDid:63907

Trust: 1.5

db:CNVDid:CNVD-2013-14742

Trust: 0.6

db:CNNVDid:CNNVD-201311-438

Trust: 0.6

sources: CNVD: CNVD-2013-14742 // BID: 63907 // CNNVD: CNNVD-201311-438

REFERENCES

url:http://www.securityfocus.com/bid/63907

Trust: 1.2

url:http://www.pirellibroadband.com/

Trust: 0.3

sources: CNVD: CNVD-2013-14742 // BID: 63907 // CNNVD: CNNVD-201311-438

CREDITS

Sebastin Magof

Trust: 0.6

sources: CNNVD: CNNVD-201311-438

SOURCES

db:CNVDid:CNVD-2013-14742
db:BIDid:63907
db:CNNVDid:CNNVD-201311-438

LAST UPDATE DATE

2022-05-17T01:45:23.686000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-14742date:2013-11-27T00:00:00
db:BIDid:63907date:2013-11-24T00:00:00
db:CNNVDid:CNNVD-201311-438date:2013-12-11T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-14742date:2013-11-27T00:00:00
db:BIDid:63907date:2013-11-24T00:00:00
db:CNNVDid:CNNVD-201311-438date:2013-11-24T00:00:00