CVE-2020-27692
04.11.2020, 21:15
The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains multiple CSRF vulnerabilities within its web management portal. Attackers can, for example, use this to update the TR-069 configuration server settings (responsible for managing devices remotely). This makes it possible to remotely reboot the device or upload malicious firmware.
Vendor | Product | Version |
---|---|---|
imomobile | verve_connect_vh510_firmware | 𝑥 < 1.0.1.6l0516 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References