vendor:
TC7200
by:
Jeroen - IT Nerdbox
7,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: TC7200
Affected Version From: STD6.01.12
Affected Version To: STD6.01.12
Patch Exists: YES
Related CWE: CVE-2014-0621
CPE: h:technicolor:tc7200
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
Technicolor TC7200 – Multiple CSRF Vulnerabilities
Multiple CSRF vulnerabilities exist in the Technicolor TC7200 modem. An attacker can exploit these vulnerabilities to perform a factory reset, disable the advanced options, remove IP filters, and remove firewall settings. No authentication is required to exploit these vulnerabilities.
Mitigation:
Ensure that the Technicolor TC7200 modem is running the latest version of the firmware. Additionally, ensure that the modem is not exposed to the public internet.