113308vdb entry
http://osvdb.org/show/osvdb/113308 CVE-2014-7281
Tenda A32 Router - Cross-Site Request Forgery
Record summary
CVE-2014-7281 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote attackers to hijack the authentication of administrators for requests that reboot the device via a request to goform/SysToolReboot.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBTenda A32 Router - Cross-Site Request ForgeryExploitDB exploitby zixianNot analyzed1 file
References
4packetstormsecurity.com
http://packetstormsecurity.com/files/128671/Tenda-A32-Cross-Site-Request-Forgery.html 34969exploit
http://www.exploit-db.com/exploits/34969 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-7281