Description
Cross-site request forgery (CSRF) vulnerability in password.cgi in Sagem F@ST 2604 253180972B allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter.
Exploits (1)
exploitdb
WORKING POC
by KinG Of PiraTeS · textwebappshardware
https://www.exploit-db.com/exploits/18504
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/73380
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/79649
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/48088
Exploit exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/18504
Scores
EPSS
0.0031
EPSS Percentile
54.4%
Details
CWE
CWE-352
Status
published
Products (2)
sagem/f\@st_2604
sagem/f\@st_2604_firmware
253180972b
Published
Oct 08, 2012
Tracked Since
Feb 18, 2026