CVE-2019-7391

ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zyxel:dsl-491hnu-b10b_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:dsl-491hnu-b10b:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:zyxel:dsl-491hnu-b1b_v2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:dsl-491hnu-b1b_v2:-:*:*:*:*:*:*:*

History

07 Nov 2023, 03:13

Type Values Removed Values Added
References
  • {'url': 'https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)', 'name': 'https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)', 'tags': ['Technical Description', 'Third Party Advisory'], 'refsource': 'MISC'}
  • () https://www.owasp.org/index.php/Cross-Site_Request_Forgery_%28CSRF%29 -
References (EXPLOIT-DB) https://www.exploit-db.com/exploits/46326/ - Exploit, Third Party Advisory, VDB Entry (EXPLOIT-DB) https://www.exploit-db.com/exploits/46326/ - Exploit, VDB Entry, Third Party Advisory

Information

Published : 2019-03-21 16:01

Updated : 2023-12-10 12:59


NVD link : CVE-2019-7391

Mitre link : CVE-2019-7391

CVE.ORG link : CVE-2019-7391


JSON object : View

Products Affected

zyxel

  • dsl-491hnu-b1b_v2
  • dsl-491hnu-b10b_firmware
  • dsl-491hnu-b1b_v2_firmware
  • dsl-491hnu-b10b
CWE
CWE-352

Cross-Site Request Forgery (CSRF)