6.8
CVSSv2

CVE-2014-2946

Published: 02/06/2014 Updated: 18/06/2014
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in api/sms/send-sms in the Web UI 11.010.06.01.858 on Huawei E303 modems with software 22.157.18.00.858 allows remote malicious users to hijack the authentication of administrators for requests that perform API operations and send SMS messages via a request element in an XML document.

Vulnerable Product Search on Vulmon Subscribe to Product

huawei e303_modem_firmware 22.157.18.00.858

huawei webui 11.010.06.01.858

huawei e303_modem ch2e303sm

Exploits

source: wwwsecurityfocuscom/bid/67747/info Huawei E303 Router is prone to a cross-site request-forgery vulnerability Exploiting this issue may allow a remote attacker to perform certain unauthorized actions This may lead to further attacks Huawei E303 Router running firmware versions CH2E303SM is vulnerable; other versions may also b ...