CVE-2015-5990
- EPSS 0.11%
- Veröffentlicht 31.12.2015 16:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site request forgery (CSRF) vulnerability on Belkin F9K1102 2 devices with firmware 2.10.17 allows remote attackers to hijack the authentication of arbitrary users.
- EPSS 1.08%
- Veröffentlicht 31.12.2015 16:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Belkin F9K1102 2 devices with firmware 2.10.17 rely on client-side JavaScript code for authorization, which allows remote attackers to obtain administrative privileges via certain changes to LockStatus and Login_Success values.
CVE-2015-5988
- EPSS 0.54%
- Veröffentlicht 31.12.2015 16:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The web management interface on Belkin F9K1102 2 devices with firmware 2.10.17 has a blank password, which allows remote attackers to obtain administrative privileges by leveraging a LAN session.
CVE-2015-5987
- EPSS 1.16%
- Veröffentlicht 31.12.2015 16:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Belkin F9K1102 2 devices with firmware 2.10.17 use an improper algorithm for selecting the ID value in the header of a DNS query, which makes it easier for remote attackers to spoof responses by predicting this value.