MidnightBSD

Advisories for philippine_long_distance_telephone

CVE-2015-5991 MEDIUM

Cross-site request forgery (CSRF) vulnerability in form2WlanSetup.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to hijack the authentication of administrators for requests that perform setup operations, as demonstrated by modifying network settings.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
philippine_long_distance_telephone speedsurf_504an_firmware gan9.8u26-4-tx-r6b018-hp.en
philippine_long_distance_telephone kasda_kw58293_firmware -
CVE-2015-5992 MEDIUM

Cross-site scripting (XSS) vulnerability in form2WlanSetup.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to inject arbitrary web script or HTML via the ssid parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
philippine_long_distance_telephone speedsurf_504an_firmware gan9.8u26-4-tx-r6b018-hp.en
philippine_long_distance_telephone kasda_kw58293_firmware -
CVE-2015-5993 HIGH

Buffer overflow in form2ping.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to cause a denial of service (device outage) via a long ipaddr parameter.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
philippine_long_distance_telephone speedsurf_504an_firmware gan9.8u26-4-tx-r6b018-hp.en
philippine_long_distance_telephone kasda_kw58293_firmware -