vendor:
ZXV10 831IIV7.5.0a_Z29_OV
by:
Mehdi Boukazoula ; Ibrahim Debeche
8.8
CVSS
HIGH
Authentication bypass + Cross Site Request forgery
287,352
CWE
Product Name: ZXV10 831IIV7.5.0a_Z29_OV
Affected Version From: v 831IIV7.5.0a_Z29_OV
Affected Version To: v 831IIV7.5.0a_Z29_OV
Patch Exists: Yes
Related CWE: N/A
CPE: h:zte:zxv10_831iiv7.5.0a_z29_ov
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
ZTE ZXDSL 831IIV7.5.0a_Z29_OV Multiple vulnerabilities
To bypass authentication, the attacker can go to URL http://192.168.1.1/accessaccount.cgi. To get request forgery, the attacker can request from his browser without cookie or any authentication, or send link to the Administrator. The script revealing sensitive information on source of page 'accessaccount.cgi' reveals the default credentials for both user and admin accounts.
Mitigation:
Install the patch provided by the vendor and change the default credentials for both user and admin accounts.