vendor:
CT-536 and HG-536
by:
SecurityFocus
9.3
CVSS
HIGH
Multiple unauthorized-access vulnerabilities, Information-disclosure vulnerability, Cross-site scripting vulnerabilities, Denial-of-service vulnerability, Buffer-overflow vulnerabilities
N/A
CWE
Product Name: CT-536 and HG-536
Affected Version From: CT-536 A101-302JAZ-C01_R05, HG-536+ A101-302JAZ-C01_R05 and A101-302JAZ-C03_R14.A2pB021g.d15h
Affected Version To: CT-536 A101-302JAZ-C01_R05, HG-536+ A101-302JAZ-C01_R05 and A101-302JAZ-C03_R14.A2pB021g.d15h
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
COMTREND CT-536 and HG-536 Multiple Remote Vulnerabilities
Attackers can exploit these issues to compromise the affected device, obtain sensitive information, execute arbitrary script code, steal cookie-based authentication credentials, and cause a denial-of-service condition. Other attacks are also possible.
Mitigation:
Update to the latest version of the firmware.