CVE-2014-4155
CVE-2014-4155
Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a request to Forms/tools_admin_1.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/127129/ZTE-WXV10-W300-Disclosure-CSRF-Default.htmlunverifiedcve_referencewww.exploit-db.com/exploits/33803unverifiedexploitdbwww.exploit-db.com/exploits/33803unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →