6.8
CVSSv2

CVE-2011-0886

Published: 08/02/2011 Updated: 09/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the SMC SMCD3G-CCR (aka Comcast Business Gateway) with firmware prior to 1.4.0.49.2 allow remote malicious users to (1) hijack the intranet connectivity of arbitrary users for requests that perform a login via goform/login, or hijack the authentication of administrators for requests that (2) enable external logins via an mso_remote_enable action to goform/RemoteRange or (3) change DNS settings via a manual_dns_enable action to goform/Basic.

Vulnerable Product Search on Vulmon Subscribe to Product

smc_networks smcd3g-ccr

smc_networks smcd3g-ccr_firmware

smc_networks smcd3g-ccr_firmware 1.4.0.42

Exploits

Trustwave's SpiderLabs Security Advisory TWSL2011-002: Vulnerabilities in Comcast DOCSIS 30 Business Gateways (D3G-CCR) wwwtrustwavecom/spiderlabs/advisories/TWSL2011-002txt Published: 2011-02-04 Version: 10 Vendor: Comcast (comcastcom) Product: Comcast DOCSIS 30 Business Gateway - D3G-CCR Version affected: Versions prior ...
Comcast DOCSIS 30 Business Gateways suffer from static credential, multiple cross site request forgery, and weak session management vulnerabilities Versions prior to 140492 are affected ...