Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-5395


Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote attackers to hijack the authentication of users for requests that (1) modify configurations, (2) send SMS messages, or have other unspecified impact via unknown vectors.


Published

2014-11-21T15:59:00.087

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-352

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei e5180s-22_firmware ≤ e5180s-22tcpu-21.270.05.01.00 Yes
Operating System huawei e3276_firmware ≤ webui-13.100.09.00.03 Yes
Operating System huawei e3276_firmware ≤ e3276s-150tcpu-22.265.03.00.00 Yes
Operating System huawei e3236_firmware ≤ webui-13.100.10.00.03 Yes
Operating System huawei e586bs-2_firmware ≤ e586bs-2tcpu-21.322.08.00.889 Yes
Operating System huawei e3236_firmware ≤ e3236s-2tcpu-22.146.29.00.00 Yes

References