MidnightBSD

Advisories for centurysys

CVE-2008-6449 MEDIUM

Cross-site request forgery (CSRF) vulnerability in multiple Century Systems routers including XR-410 before 1.6.9, XR-510 before 3.5.3, XR-440 before 1.7.8, and other XR series routers from XR-510 to XR-730 allows remote attackers to modify configuration as the administrator via unknown vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
centurysys xr-410 *
centurysys xr-1100 *
centurysys xr-640-l2 *
centurysys xr-540 *
centurysys xr-640 *
centurysys xr-510 *
centurysys xr-440 *
centurysys xr-410-l2 *
centurysys xr-730 *