JVN#88575577
Multiple Yamaha routers vulnerable to cross-site request forgery
Overview
The web interface in multiple Yamaha routers is vulnerable to cross-site request forgery.
Products Affected
- SRT100
- RT58i
- RT57i
- RT56v
- RTA55i
- RTA54i
- RTA52i
- RTA50i
- RT60w
- RTW65i
- RTW65b
- RTX1100
- RTX1500
- RT107e
- RTV700
- RTX1000
- RT80i
- RTV01
Description
Multiple Yamaha routers provide a web-based interface for users to configure the settings of the routers.
The web interface is vulnerable to cross-site request forgery.
Impact
If the administrator views a malicious website while logged onto the web interface, the password and other configuration settings can be modified.
Solution
Update the Software
Apply the latest firmware provided by the vendors.
Change settings of the router
Change settings of the router so that no configuration settings can be modified through a web browser.
For more information, refer to the vendors' websites.
Vendor Status
Vendor | Status | Last Update | Vendor Notes |
---|---|---|---|
Yamaha Corporation | Vulnerable | 2008/01/28 | |
NEC Corporation | Vulnerable | 2008/01/31 |
JPCERT/CC Addendum
On February 1, Yamaha reported that RTV01 was added to and RT52pro was removed from the products_affected.Vulnerability Analysis by JPCERT/CC
Analyzed on 2008.01.28
Measures | Conditions | Severity |
---|---|---|
Access Required | Routed - can be attacked over the Internet using packets |
|
Authentication | None - anonymous or no authentication (IP addresses do not count) |
|
User Interaction Required | Simple - the user must be convinced to take a standard action that does not feel harmful to most users, such as click on a link or view a file |
|
Exploit Complexity | Low - little to no expertise and/or luck required to exploit (cross-site scripting) |
|
Credit
Hirotaka Katagiri reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendors under Information Security Early Warning Partnership.
Other Information
JPCERT Alert | |
JPCERT Reports | |
CERT Advisory | |
CPNI Advisory | |
TRnotes | |
CVE | |
JVN iPedia |
JVNDB-2008-000005 |
Update History
- 2008/05/21
- JVN English site opened and the first English advisory of this issue was published.
- 2008/07/17
- Information under the section "References" was added.