Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-20621


Cross-site request forgery (CSRF) vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.


Published

2021-01-28T11:15:13.793

Last Modified

2024-11-21T05:46:53.613

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-352

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System aterm wg2600hp_firmware ≤ 1.0.2 Yes
Hardware aterm wg2600hp - No
Operating System aterm wg2600hp2_firmware ≤ 1.0.2 Yes
Hardware aterm wg2600hp2 - No

References