CVE-2016-1228
Published Jul 3, 2016
Last updated 3 years ago
Overview
- Description
- Cross-site request forgery (CSRF) vulnerability on NTT EAST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1006 and earlier and NTT WEST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1005 and earlier allows remote attackers to hijack the authentication of arbitrary users.
- Source
- vultures@jpcert.or.jp
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-352
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:ntt-west:pr-400mi_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A792CE36-D838-4D25-ADAB-898BE7F3439B", "versionEndIncluding": "07.00.1005" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:ntt-west:pr-400mi:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A55EB69F-E103-4A45-8083-A2D6A3AD36C8" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:ntt-west:rt-400mi_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "858278B2-7203-427C-988C-3104970A7E00", "versionEndIncluding": "07.00.1005" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:ntt-west:rt-400mi:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D76D559B-2936-41B9-A810-1658CE125A5A" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:ntt-west:rv-440mi_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DEC56ACD-3B81-4434-AA4D-DAEAF8442434", "versionEndIncluding": "07.00.1005" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:ntt-west:rv-440mi:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C2561A87-C99A-4E27-A0AE-E22EE2513735" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:ntt-east:pr-400mi_firmware:07.00.1006:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4E897E4B-6058-4ECC-9309-CEB09119F45E" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:ntt-east:pr-400mi:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7AF589E8-4E1A-43B2-9F44-513D393C2945" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:ntt-east:rt-400mi_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B964A954-08EB-416E-BDAE-D66F0C1B5366", "versionEndIncluding": "07.00.1006" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:ntt-east:rt-400mi:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "64CEFE29-5AF9-4935-B084-6B556921AAF0" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:ntt-east:rv-440mi_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "57B97F48-D979-4BD1-B327-5852BA71E360", "versionEndIncluding": "07.00.1006" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:ntt-east:rv-440mi:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "154E8DF0-AAB4-4926-AD4E-2EB043736810" } ], "operator": "OR" } ], "operator": "AND" } ]