LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2017-20221

telesquare · sdt-cs3b1 firmware

Published
CVSS4.3
Severitymedium
WeaknessCWE-352
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Description

Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains a cross-site request forgery vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting missing request validation. Attackers can craft malicious web pages that perform administrative actions when visited by logged-in users, enabling command execution with router privileges.

References

← Back to the CVE Tracker

Our coverage of CVE-2017-20221

No stories yet. This page updates automatically when we publish reporting that references CVE-2017-20221.