RSS   Vulnerabilities for 'R10000 firmware'   RSS

2015-12-31
 
CVE-2015-7279

 

 
Amped Wireless R10000 devices with firmware 2.5.2.11 use an improper algorithm for selecting the ID value in the header of a DNS query, which makes it easier for remote attackers to spoof responses by predicting this value.

 
 
CVE-2015-7278

 

 
Cross-site request forgery (CSRF) vulnerability on Amped Wireless R10000 devices with firmware 2.5.2.11 allows remote attackers to hijack the authentication of arbitrary users.

 
 
CVE-2015-7277

 

 
The web administration interface on Amped Wireless R10000 devices with firmware 2.5.2.11 has a default password of admin for the admin account, which allows remote attackers to obtain administrative privileges by leveraging a LAN session.

 


Copyright 2021, cxsecurity.com

 

Back to Top