vendor:
Surfboard Gateway
by:
Blessen Thomas
7,5
CVSS
HIGH
Cross-site request forgery
352
CWE
Product Name: Surfboard Gateway
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: CVE-2014-3778
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2014
Motorola SBG901 Wireless Modem CSRF Vulnerability
It was observed that this modem's Web Application, is vulnerable to Cross-site request forgery through which attacker could manipulate user data via sending the victim malicious crafted url. At attacker could change the username,password,dns service and host name of the victim's account without the victim's knowledge.
Mitigation:
The vendor has stated that the product is no longer in production and due end of life status product, so no fix is available.