CVE-2008-6605
Cross-site request forgery (CSRF) vulnerability in the xslt script in the web-based management interface on the 2wire 1701HG, 1800HW, 2071HG, and 2700HG with firmware 3.17.5, 3.7.1, 4.25.19, or 5.29.51 allows remote attackers to hijack the intranet connectivity of arbitrary users for requests that cause a denial of service (network outage) via a page parameter with a % (percent) character followed by a non-alphanumeric character.
Published:Apr 6, 2009
Last Modified:Apr 23, 2026
EPS:Apr 6, 2009
EPSS Score:0.00432
CVSS Score:6.8
Affected Products
Vendor
Product
Action
Vendor
2wire
Product
1701hg
2wire
1701hg
Vendor
2wire
Product
1800hw
2wire
1800hw
Vendor
2wire
Product
2071hg
2wire
2071hg
Vendor
2wire
Product
2700hg
2wire
2700hg
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
