Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the web management interface in the ZyXEL P-330W router allow remote attackers to hijack the authentication of administrators for requests that (1) enable remote router management via goform/formRmtMgt or (2) modify the administrator password via goform/formPasswordSetup.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ZyXEL P-330W跨站脚本执行及请求伪造漏洞
Vulnerability Description
ZyXEL P-330W是一款无线宽带路由器。 ZyXEL P-330W处理用户请求时存在输入验证漏洞,远程攻击者可能利用此漏洞攻击用户系统。 ZyXEL P-330W的ping.asp文件中没有正确地过滤对pingstr参数的输入便返回给了用户,用户通过HTTP请求执行各种操作,没有验证请求的有效性,攻击者通过伪造请求执行各种攻击,如更改管理员口令。
CVSS Information
N/A
Vulnerability Type
N/A