VulnerabilityModified
CVE-2014-9143
Open redirect vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the failrefer parameter.
MEDIUM 4.3EPSS 3.98%
Does this matter?
Lower severity and a low EPSS score (3.98%). Track it; it rarely justifies an emergency change on its own.
Description
Open redirect vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the failrefer parameter.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 3.98% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-17
- Affected
- technicolor/td5130 router firmware
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/129374/ADSL2-2.05.C29GV-XSS-URL-Redirect-Command-Injection.htmlExploit
- http://www.exploit-db.com/exploits/35462Exploit
- http://www.securityfocus.com/archive/1/534143/100/0/threaded
- http://packetstormsecurity.com/files/129374/ADSL2-2.05.C29GV-XSS-URL-Redirect-Command-Injection.htmlExploit
- http://www.exploit-db.com/exploits/35462Exploit
- http://www.securityfocus.com/archive/1/534143/100/0/threaded
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.