Huawei.HG510.CSRF
Description
This indicates an attack attempt to exploit a security bypass and cross-site request forgery vulnerability in the Huawei HG510 interface.
The vulnerability is a combination of a lack of cross-site forgery protection and a lack of validation when accessing rebootinfo.cgi. As a result, an attacker can inject a crafted uri and cause a Denial of Service to a valid user.
Affected Products
Huawei HG510
Impact
System Compromise: Remote attackers can gain control of vulnerable systems
Recommended Actions
Refer to the vendor's website for suggested workaround.
http://www.huawei.com/en/
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2020-12-02 | 16.972 |