CVE-2017-12589

ToMAX R60G R60GV2-V2.0-v.2.6.3-170330 devices do not have any protection against a CSRF attack.
References
Link Resource
https://iscouncil.blogspot.com/2017/08/cross-site-request-forgery_11.html Exploit Technical Description
http://www.securityfocus.com/bid/100438 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tomaxcom:r60g_firmware:2.6.3-170330:*:*:*:*:*:*:*
cpe:2.3:h:tomaxcom:r60g:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tomaxcom:r60gv2_firmware:2.6.3-170330:*:*:*:*:*:*:*
cpe:2.3:h:tomaxcom:r60gv2:-:*:*:*:*:*:*:*

Information

Published : 2017-08-18 10:29

Updated : 2017-08-26 02:10


NVD link : CVE-2017-12589

Mitre link : CVE-2017-12589


JSON object : View

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

Advertisement

dedicated server usa

Products Affected

tomaxcom

  • r60g
  • r60gv2
  • r60g_firmware
  • r60gv2_firmware