Vulnerability Description
EE 4GEE WiFi MBB (before EE60_00_05.00_31) devices have CSRF, related to goform/AddNewProfile, goform/setWanDisconnect, goform/setSMSAutoRedirectSetting, goform/setReset, and goform/uploadBackupSettings.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ee | 4Gee Wifi Mbb Firmware | <= ee60_00_05.00_25 |
| Ee | 4Gee Wifi Mbb | - |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2017/Sep/13ExploitMailing ListThird Party Advisory
- https://blog.jameshemmings.co.uk/2017/08/24/ee-4gee-mobile-wifi-router-multiple-ExploitThird Party Advisory
- https://github.com/JamesIT/vuln-advisories-/blob/master/EE-4GEE-Multiple-Vulns/CExploitThird Party Advisory
- https://github.com/JamesIT/vuln-advisories-/blob/master/EE-4GEE-Multiple-Vulns/CExploitThird Party Advisory
- https://github.com/JamesIT/vuln-advisories-/blob/master/EE-4GEE-Multiple-Vulns/CExploitThird Party Advisory
- https://github.com/JamesIT/vuln-advisories-/blob/master/EE-4GEE-Multiple-Vulns/CExploitThird Party Advisory
- https://github.com/JamesIT/vuln-advisories-/blob/master/EE-4GEE-Multiple-Vulns/CExploitThird Party Advisory
- http://seclists.org/fulldisclosure/2017/Sep/13ExploitMailing ListThird Party Advisory
- https://blog.jameshemmings.co.uk/2017/08/24/ee-4gee-mobile-wifi-router-multiple-ExploitThird Party Advisory
- https://github.com/JamesIT/vuln-advisories-/blob/master/EE-4GEE-Multiple-Vulns/CExploitThird Party Advisory
- https://github.com/JamesIT/vuln-advisories-/blob/master/EE-4GEE-Multiple-Vulns/CExploitThird Party Advisory
- https://github.com/JamesIT/vuln-advisories-/blob/master/EE-4GEE-Multiple-Vulns/CExploitThird Party Advisory
- https://github.com/JamesIT/vuln-advisories-/blob/master/EE-4GEE-Multiple-Vulns/CExploitThird Party Advisory
- https://github.com/JamesIT/vuln-advisories-/blob/master/EE-4GEE-Multiple-Vulns/CExploitThird Party Advisory
FAQ
What is CVE-2017-14267?
CVE-2017-14267 is a vulnerability with a CVSS score of 8.8 (HIGH). EE 4GEE WiFi MBB (before EE60_00_05.00_31) devices have CSRF, related to goform/AddNewProfile, goform/setWanDisconnect, goform/setSMSAutoRedirectSetting, goform/setReset, and goform/uploadBackupSettin...
How severe is CVE-2017-14267?
CVE-2017-14267 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14267?
Check the references section above for vendor advisories and patch information. Affected products include: Ee 4Gee Wifi Mbb Firmware, Ee 4Gee Wifi Mbb.