Cross-Site Request Forgery Vulnerabilities in Motorola Surfboard Modems
CVE-2008-2002

Currently unrated

Key Information:

Vendor
Motorola
Status
Vendor
CVE Published:
28 April 2008

Summary

The Motorola Surfboard modem with software version SB5100-2.3.3.0-SCM00-NOSH is susceptible to multiple cross-site request forgery vulnerabilities. An attacker can exploit these vulnerabilities to remotely initiate a denial of service by triggering a device reboot through the 'Restart Cable Modem' functionality or executing a hard reset by executing the 'Reset All Defaults' action. Both vulnerabilities interact through the BUTTON_INPUT parameter located in configdata.html, enabling unauthorized users to disrupt the device's normal operation.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.