Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in the management interface in multiple Yamaha RT series routers allows remote attackers to change password settings and probably other configuration settings as administrators via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yamaha | Rt107E | All versions |
| Yamaha | Rt52Pro | All versions |
| Yamaha | Rt56V | All versions |
| Yamaha | Rt57I | All versions |
| Yamaha | Rt58I | All versions |
| Yamaha | Rt60W | All versions |
| Yamaha | Rt80I | All versions |
| Yamaha | Rta50I | All versions |
| Yamaha | Rta52I | All versions |
| Yamaha | Rta54I | All versions |
| Yamaha | Rta55I | All versions |
| Yamaha | Rtv700 | All versions |
| Yamaha | Rtw65B | All versions |
| Yamaha | Rtw65I | All versions |
| Yamaha | Rtx1000 | All versions |
| Yamaha | Rtx1100 | All versions |
| Yamaha | Rtx1500 | All versions |
| Yamaha | Srt100 | All versions |
Related Weaknesses (CWE)
References
- http://jvn.jp/jp/JVN%2388575577/index.html
- http://secunia.com/advisories/28690
- http://www.rtpro.yamaha.co.jp/RT/FAQ/Security/JVN88575577.html
- http://www.securityfocus.com/bid/27491
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40015
- http://jvn.jp/jp/JVN%2388575577/index.html
- http://secunia.com/advisories/28690
- http://www.rtpro.yamaha.co.jp/RT/FAQ/Security/JVN88575577.html
- http://www.securityfocus.com/bid/27491
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40015
FAQ
What is CVE-2008-0524?
CVE-2008-0524 is a vulnerability with a CVSS score of 7.5 (HIGH). Cross-site request forgery (CSRF) vulnerability in the management interface in multiple Yamaha RT series routers allows remote attackers to change password settings and probably other configuration se...
How severe is CVE-2008-0524?
CVE-2008-0524 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-0524?
Check the references section above for vendor advisories and patch information. Affected products include: Yamaha Rt107E, Yamaha Rt52Pro, Yamaha Rt56V, Yamaha Rt57I, Yamaha Rt58I.