HIGH · 8.8

CVE-2016-1228

Cross-site request forgery (CSRF) vulnerability on NTT EAST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1006 and earlier and NTT WEST Hikari Denwa routers with firmware P...

Vulnerability Description

Cross-site request forgery (CSRF) vulnerability on NTT EAST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1006 and earlier and NTT WEST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1005 and earlier allows remote attackers to hijack the authentication of arbitrary users.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Ntt-WestPr-400Mi Firmware<= 07.00.1005
Ntt-WestPr-400Mi-
Ntt-WestRt-400Mi Firmware<= 07.00.1005
Ntt-WestRt-400Mi-
Ntt-WestRv-440Mi Firmware<= 07.00.1005
Ntt-WestRv-440Mi-
Ntt-EastPr-400Mi Firmware07.00.1006
Ntt-EastPr-400Mi-
Ntt-EastRt-400Mi Firmware<= 07.00.1006
Ntt-EastRt-400Mi-
Ntt-EastRv-440Mi Firmware<= 07.00.1006
Ntt-EastRv-440Mi-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-1228?

CVE-2016-1228 is a vulnerability with a CVSS score of 8.8 (HIGH). Cross-site request forgery (CSRF) vulnerability on NTT EAST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1006 and earlier and NTT WEST Hikari Denwa routers with firmware P...

How severe is CVE-2016-1228?

CVE-2016-1228 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-1228?

Check the references section above for vendor advisories and patch information. Affected products include: Ntt-West Pr-400Mi Firmware, Ntt-West Pr-400Mi, Ntt-West Rt-400Mi Firmware, Ntt-West Rt-400Mi, Ntt-West Rv-440Mi Firmware.