6.8
CVSSv2

CVE-2012-4746

Published: 31/08/2012 Updated: 03/09/2012
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 690
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in accessaccount.cgi in ZTE ZXDSL 831IIV7.5.0a_Z29_OV allows remote malicious users to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

zte zxdsl 831iiv7.5.0a_z29_ov

Exploits

# Exploit Title: ZTE Change admin password # Author: Nuevo Asesino # Version: ZTE Inc, Software Release ZXDSL 831IIV750a_Z29_OV ################################################################################################# <html> <body onload="javascript:documentforms[0]submit()"> <H2>Exploit By Nuevo Asesino </H2> & ...
# Exploit Title: ZTE ZXDSL 831IIV750a_Z29_OV Multiple vulnerabilities # Date: 28 / 10 / 2011 # Authors: Mehdi Boukazoula ; Ibrahim Debeche # Software Link with patch : # Version: v 831IIV750a_Z29_OV # Tested on: v 831IIV750a_Z29_OV, May Affect all ZTE routers !! # Description : 1 - Authentication bypass + Cross Site Request forgery To b ...