Intrusion Prevention

Huawei.HG510.CSRF

Description

This indicates an attack attempt to exploit a security bypass and cross-site request forgery vulnerability in the Huawei HG510 interface.
The vulnerability is a combination of a lack of cross-site forgery protection and a lack of validation when accessing rebootinfo.cgi. As a result, an attacker can inject a crafted uri and cause a Denial of Service to a valid user.

Affected Products

Huawei HG510

Impact

System Compromise: Remote attackers can gain control of vulnerable systems

Recommended Actions

Refer to the vendor's website for suggested workaround.
http://www.huawei.com/en/

Other References

0155 38591