CVE-2018-10080

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
13/04/2018
Last modified:
22/05/2018

Description

Secutech RiS-11, RiS-22, and RiS-33 devices with firmware V5.07.52_es_FRI01 allow DNS settings changes via a goform/AdvSetDns?GO=wan_dns.asp request in conjunction with a crafted admin cookie.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:secutech_project:ris-11_firmware:5.07.52_es_fri01:*:*:*:*:*:*:*
cpe:2.3:h:secutech_project:ris-11:-:*:*:*:*:*:*:*
cpe:2.3:o:secutech_project:ris-22_firmware:5.07.52_es_fri01:*:*:*:*:*:*:*
cpe:2.3:h:secutech_project:ris-22:-:*:*:*:*:*:*:*
cpe:2.3:o:secutech_project:ris-33_firmware:5.07.52_es_fri01:*:*:*:*:*:*:*
cpe:2.3:h:secutech_project:ris-33:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools