6.8
CVSSv2

CVE-2014-8654

Published: 06/11/2014 Updated: 08/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway hardware 1.0 with firmware CH6640-3.5.11.7-NOSH allow remote malicious users to hijack the authentication of administrators for requests that (1) have unspecified impact on DDNS configuration via a request to basicDDNS.html, (2) change the wifi password via the psKey parameter to setWirelessSecurity.html, (3) add a static MAC address via the MacAddress parameter in an add_static action to setBasicDHCP1.html, or (4) enable or disable UPnP via the UPnP parameter in an apply action to setAdvancedOptions.html.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

compal_broadband_networks firmware ch6640-3.5.11.7-nosh

compal_broadband_networks ch664oe_wireless_gateway 1.0

compal_broadband_networks cg6640e_wireless_gateway 1.0

Exploits

CBN CH6640E/CG6640E Wireless Gateway Series Multiple Vulnerabilities Vendor: Compal Broadband Networks (CBN), Inc Product web page: wwwicbncomtw Affected version: Model: CH6640 and CH6640E Hardware version: 10 Firmware version: CH6640-35117-NOSH Boot version: PSPU-Boot(BBU) 10 ...