Huawei HiLink E3236 and E3276 Cross-Site Request Forgery Vulnerability
Release date:
Updated on:
Affected Systems:
Huawei E3256
Huawei E3236
Description:
--------------------------------------------------------------------------------
Bugtraq id: 69162
Huawei HiLink E3236 and E3276 are HSPA + 21 Mbps USB modems.
The CSRF vulnerability exists in Huawei HiLink E3236/E3276 products. When users use these products to access websites containing malicious scripts, malicious scripts can use users' personal computers to illegally access E3236/E3276 products, modify its configuration or use its functions.
<* Source: Andreas Lindh
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Huawei
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-360246.htm
This article permanently updates the link address: