CVE-2019-5986
Cross-site request forgery (CSRF) vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firmware version Ver.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.78%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cross-site request forgery (CSRF) vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firmware version Ver. 19.41 and earlier, PR-S300HI/RT-S300HI/RV-S340HI firmware version Ver.19.01.0005 and earlier, PR-S300SE/RT-S300SE/RV-S340SE firmware version Ver.19.40 and earlier, PR-400NE/RT-400NE/RV-440NE firmware version Ver.7.42 and earlier, PR-400KI/RT-400KI/RV-440KI firmware version Ver.07.00.1010 and earlier, PR-400MI/RT-400MI/RV-440MI firmware version Ver. 07.00.1012 and earlier, PR-500KI/RT-500KI firmware version Ver.01.00.0090 and earlier, RS-500KI firmware version Ver.01.00.0070 and earlier, PR-500MI/RT-500MI firmware version Ver.01.01.0014 and earlier, and RS-500MI firmware version Ver.03.01.0019 and earlier, and Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firmware version Ver. 19.41 and earlier, PR-S300HI/RT-S300HI/RV-S340HI firmware version Ver.19.01.0005 and earlier, PR-S300SE/RT-S300SE/RV-S340SE firmware version Ver.19.40 and earlier, PR-400NE/RT-400NE/RV-440NE firmware version Ver.7.42 and earlier, PR-400KI/RT-400KI/RV-440KI firmware version Ver.07.00.1010 and earlier, PR-400MI/RT-400MI/RV-440MI firmware version Ver. 07.00.1012 and earlier, PR-500KI/RT-500KI firmware version Ver.01.00.0090 and earlier, and PR-500MI/RT-500MI firmware version Ver.01.01.0011 and earlier) allow remote attackers to hijack the authentication of administrators via unspecified vectors.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.78% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- ntt-east/pr-s300ne firmware · ntt-east/rt-s300ne firmware · ntt-east/rv-s340ne firmware · ntt-east/pr-s300hi firmware · ntt-east/rt-s300hi firmware · ntt-east/rv-s340hi firmware · ntt-east/pr-s300se firmware · ntt-east/rt-s300se firmware · ntt-east/rv-s340se firmware · ntt-east/pr-400ne firmware · ntt-east/rt-400ne firmware · ntt-east/rv-440ne firmware · ntt-east/pr-400ki firmware · ntt-east/rt-400ki firmware · ntt-east/rv-440ki firmware · ntt-east/pr-400mi firmware · ntt-east/rt-400mi firmware · ntt-east/rv-440mi firmware · ntt-east/pr-500ki firmware · ntt-east/rt-500ki firmware · +26 more
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN43172719/index.htmlThird Party Advisory, VDB Entry
- https://www.ntt-west.co.jp/kiki/support/flets/hgw/190626.htmlVendor Advisory
- http://jvn.jp/en/jp/JVN43172719/index.htmlThird Party Advisory, VDB Entry
- https://www.ntt-west.co.jp/kiki/support/flets/hgw/190626.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.