Cross-site request forgery (CSRF) vulnerability in multiple Century Systems routers including XR-410 before 1.6.9, XR-510 before 3.5.3, XR-440 before 1.7.8, and other XR series routers from XR-510 to XR-730 allows remote attackers to modify configuration as the administrator via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| centurysys | xr-410 | * |
| centurysys | xr-1100 | * |
| centurysys | xr-640-l2 | * |
| centurysys | xr-540 | * |
| centurysys | xr-640 | * |
| centurysys | xr-510 | * |
| centurysys | xr-440 | * |
| centurysys | xr-410-l2 | * |
| centurysys | xr-730 | * |