Description
Cross-site request forgery (CSRF) vulnerability in multiple Century Systems routers including XR-410 before 1.6.9, XR-510 before 3.5.3, XR-440 before 1.7.8, and other XR series routers from XR-510 to XR-730 allows remote attackers to modify configuration as the administrator via unknown vectors.
Affected products
- centurysys / xr-11001.6.2
- centurysys / xr-4101.6.8
- centurysys / xr-410-l21.6.1
- centurysys / xr-4401.7.7
- centurysys / xr-5103.5.0
- centurysys / xr-5403.5.2
- centurysys / xr-6401.6.7
- centurysys / xr-640-l21.6.1
- centurysys / xr-7303.5.0