Vulnerability Description
NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 are vulnerable to CSRF attacks, as demonstrated by using administration.html to disable the firewall. They does not contain any token that can mitigate CSRF vulnerabilities within the device.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netcomm | 4Gt101W Software | 1.1.8.8 |
| Netcomm | 4Gt101W Bootloader | 1.1.3 |
Related Weaknesses (CWE)
References
- https://iscouncil.blogspot.com/2017/07/cross-site-request-forgery.htmlThird Party Advisory
- https://iscouncil.blogspot.com/2017/07/cross-site-request-forgery.htmlThird Party Advisory
FAQ
What is CVE-2017-11646?
CVE-2017-11646 is a vulnerability with a CVSS score of 8.8 (HIGH). NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 are vulnerable to CSRF attacks, as demonstrated by using administration.html to disable the firewall. They...
How severe is CVE-2017-11646?
CVE-2017-11646 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-11646?
Check the references section above for vendor advisories and patch information. Affected products include: Netcomm 4Gt101W Software, Netcomm 4Gt101W Bootloader.