Skip to content

CVE-2014-4155

Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a request to Forms/tools_admin_1.

Ver en NVD

Severidad

N/A

EPSS

Probabilidad de explotación (próx. 30 días): 0.0034 (0.3%)
Percentil: 56.4%
EPSS: 2026-05-06

Afecta

zte:zxv10_w300_firmwarezte:zxv10_w300

Descripción técnica

Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a request to Forms/tools_admin_1.

Publicada: 19/6/2014, 14:55:08
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo