6.8
CVSSv2

CVE-2014-8331

Published: 20/10/2014 Updated: 08/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3236 before E3276sTCPU-V200R002B470D13SP00C00 and E3276sWebUI-V100R007B100D03SP01C03 and E3276 before E3236sTCPU-V200R002B146D41SP00C00 and E3236sWebUI-V100R007B100D03SP01C03 allow remote malicious users to hijack the authentication of administrators for requests that (1) change configuration settings or (2) use device functions.

Vulnerable Product Search on Vulmon Subscribe to Product

huawei e3236 firmware webui-13.100.10.00.03

huawei e3276 firmware e3276s-150tcpu-22.265.03.00.00

huawei e3276 firmware webui-13.100.09.00.03

huawei e3236 firmware e3236s-2tcpu-22.146.29.00.00