vendor:
Flybox - Router (Web-Application) B660 3G/4G
by:
Vulnerability Laboratory
4,4
CVSS
MEDIUM
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Flybox - Router (Web-Application) B660 3G/4G
Affected Version From: Huawei Flybox B660 3G/4G Router
Affected Version To: Huawei Flybox B660 3G/4G Router
Patch Exists: NO
Related CWE: N/A
CPE: h:huawei:flybox_b660_3g/4g_router
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
Huawei Flybox B660 – (POST SMS) CSRF Web Vulnerability
A remote cross-site request forgery vulnerability has been discovered in the official Huawei Flybox B660 3G/4G router product series. The security vulnerability allows a remote attacker to perform unauthenticated application requests with non-expired browser session credentials to unauthorized execute specific backend functions. The vulnerability is located in the `/htmlcode/html/sms.cgi` and `/htmlcode/html/sms_new.asp` modules and the `RequestFile` parameter of the localhost path URL. Remote attackers are able to send sms messages as malicious bomb to other phone numbers from any Huawei Flybox B660 via unauthenticated POST method request.
Mitigation:
Implement proper authentication and authorization controls to prevent unauthorized access to the application.