6.8
CVSSv2

CVE-2014-0621

Published: 08/01/2014 Updated: 05/05/2014
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote malicious users to hijack the authentication of administrators for requests that (1) perform a factory reset via a request to goform/system/factory, (2) disable advanced options via a request to goform/advanced/options, (3) remove ip-filters via the IpFilterAddressDelete1 parameter to goform/advanced/ip-filters, or (4) remove firewall settings via the cbFirewall parameter to goform/advanced/firewall.

Vulnerable Product Search on Vulmon Subscribe to Product

technicolor tc7200_firmware std6.01.12

technicolor tc7200 -

Exploits

# Exploit Title: Technicolor TC7200 - Multiple CSRF Vulnerabilities # Google Dork: N/A # Date: 02-01-2013 # Exploit Author: Jeroen - IT Nerdbox # Vendor Homepage: wwwtechnicolorcom/en/solutions-services/connected-home/modems-gatew ays/cable-modems-gateways/tc7200-tc7300 # Software Link: N/A # Version: STD60112 # Tested on: N/A # CVE : CV ...
Technicolor TC7200 suffers from multiple cross site request forgery vulnerabilities ...