CVE-2016-1228

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
03/07/2016
Last modified:
12/04/2025

Description

Cross-site request forgery (CSRF) vulnerability on NTT EAST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1006 and earlier and NTT WEST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1005 and earlier allows remote attackers to hijack the authentication of arbitrary users.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ntt-west:pr-400mi_firmware:*:*:*:*:*:*:*:* 07.00.1005 (including)
cpe:2.3:h:ntt-west:pr-400mi:-:*:*:*:*:*:*:*
cpe:2.3:o:ntt-west:rt-400mi_firmware:*:*:*:*:*:*:*:* 07.00.1005 (including)
cpe:2.3:h:ntt-west:rt-400mi:-:*:*:*:*:*:*:*
cpe:2.3:o:ntt-west:rv-440mi_firmware:*:*:*:*:*:*:*:* 07.00.1005 (including)
cpe:2.3:h:ntt-west:rv-440mi:-:*:*:*:*:*:*:*
cpe:2.3:o:ntt-east:pr-400mi_firmware:07.00.1006:*:*:*:*:*:*:*
cpe:2.3:h:ntt-east:pr-400mi:-:*:*:*:*:*:*:*
cpe:2.3:o:ntt-east:rt-400mi_firmware:*:*:*:*:*:*:*:* 07.00.1006 (including)
cpe:2.3:h:ntt-east:rt-400mi:-:*:*:*:*:*:*:*
cpe:2.3:o:ntt-east:rv-440mi_firmware:*:*:*:*:*:*:*:* 07.00.1006 (including)
cpe:2.3:h:ntt-east:rv-440mi:-:*:*:*:*:*:*:*