Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in the xslt script in the web-based management interface on the 2wire 1701HG, 1800HW, 2071HG, and 2700HG with firmware 3.17.5, 3.7.1, 4.25.19, or 5.29.51 allows remote attackers to hijack the intranet connectivity of arbitrary users for requests that cause a denial of service (network outage) via a page parameter with a % (percent) character followed by a non-alphanumeric character.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
2Wire DSL Routers 'xslt' 脚本 拒绝服务漏洞
Vulnerability Description
装载了固件3.17.5、3.7.1、4.25.19或5.29.51的2wire 1701HG, 1800HW, 2071HG和2700HG上的web管理界面中的xslt脚本存在跨站请求伪造漏洞。远程攻击者可以借助一个页参数,劫持任意用户的内网连接请求。该请求会造成拒绝服务攻击(网络损耗)。而这个页参数带有一个%字符,紧跟在%字符后面的是一个非文字数字的字符。
CVSS Information
N/A
Vulnerability Type
N/A