CVE-2014-9019
ZTE ZXDSL 831CII - Cross-Site Request Forgery via adminpasswd.cgi
Title source: llmDescription
Multiple cross-site request forgery (CSRF) vulnerabilities in ZTE ZXDSL 831CII allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin user name or (2) conduct cross-site scripting (XSS) attacks via the sysUserName parameter in a save action to adminpasswd.cgi or (3) change the admin user password via the sysPassword parameter in a save action to adminpasswd.cgi.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/533930/100/0/threaded
Exploit x_refsource_misc
http://packetstormsecurity.com/files/129016/ZTE-831CII-Hardcoded-Credential-XSS-CSRF.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98585
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/70984
Scores
EPSS
0.0018
EPSS Percentile
39.4%
Details
CWE
CWE-352
Status
published
Products (1)
zte/zxdsl
831cii
Published
Nov 20, 2014
Tracked Since
Feb 18, 2026