National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

CVE-2019-5986 Detail

Current Description

Cross-site request forgery (CSRF) vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firmware version Ver. 19.41 and earlier, PR-S300HI/RT-S300HI/RV-S340HI firmware version Ver.19.01.0005 and earlier, PR-S300SE/RT-S300SE/RV-S340SE firmware version Ver.19.40 and earlier, PR-400NE/RT-400NE/RV-440NE firmware version Ver.7.42 and earlier, PR-400KI/RT-400KI/RV-440KI firmware version Ver.07.00.1010 and earlier, PR-400MI/RT-400MI/RV-440MI firmware version Ver. 07.00.1012 and earlier, PR-500KI/RT-500KI firmware version Ver.01.00.0090 and earlier, RS-500KI firmware version Ver.01.00.0070 and earlier, PR-500MI/RT-500MI firmware version Ver.01.01.0014 and earlier, and RS-500MI firmware version Ver.03.01.0019 and earlier, and Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firmware version Ver. 19.41 and earlier, PR-S300HI/RT-S300HI/RV-S340HI firmware version Ver.19.01.0005 and earlier, PR-S300SE/RT-S300SE/RV-S340SE firmware version Ver.19.40 and earlier, PR-400NE/RT-400NE/RV-440NE firmware version Ver.7.42 and earlier, PR-400KI/RT-400KI/RV-440KI firmware version Ver.07.00.1010 and earlier, PR-400MI/RT-400MI/RV-440MI firmware version Ver. 07.00.1012 and earlier, PR-500KI/RT-500KI firmware version Ver.01.00.0090 and earlier, and PR-500MI/RT-500MI firmware version Ver.01.01.0011 and earlier) allow remote attackers to hijack the authentication of administrators via unspecified vectors.

Source:  MITRE
View Analysis Description

Severity



CVSS 3.x Severity and Metrics:

NIST CVSS score
NIST: NVD
Base Score: 8.8 HIGH
Vector:  CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

Hyperlink Resource
http://jvn.jp/en/jp/JVN43172719/index.html Third Party Advisory VDB Entry
https://www.ntt-west.co.jp/kiki/support/flets/hgw/190626.html Vendor Advisory

Weakness Enumeration

CWE-ID CWE Name Source
CWE-352 Cross-Site Request Forgery (CSRF) NIST  

Known Affected Software Configurations Switch to CPE 2.3

Configuration 1 ( hide )
 cpe:/o:ntt-east:pr-s300ne_firmware
     Show Matching CPE(s)
Up to (including)
19.41
Running on/with
 cpe:/h:ntt-east:pr-s300ne:-
     Show Matching CPE(s)

Configuration 2 ( hide )
 cpe:/o:ntt-east:rt-s300ne_firmware
     Show Matching CPE(s)
Up to (including)
19.41
Running on/with
 cpe:/h:ntt-east:rt-s300ne:-
     Show Matching CPE(s)

Configuration 3 ( hide )
 cpe:/o:ntt-east:rv-s340ne_firmware
     Show Matching CPE(s)
Up to (including)
19.41
Running on/with
 cpe:/h:ntt-east:rv-s340ne:-
     Show Matching CPE(s)

Configuration 4 ( hide )
 cpe:/o:ntt-east:pr-s300hi_firmware
     Show Matching CPE(s)
Up to (including)
19.01.0005
Running on/with
 cpe:/h:ntt-east:pr-s300hi:-
     Show Matching CPE(s)

Configuration 5 ( hide )
 cpe:/o:ntt-east:rt-s300hi_firmware
     Show Matching CPE(s)
Up to (including)
19.01.0005
Running on/with
 cpe:/h:ntt-east:rt-s300hi:-
     Show Matching CPE(s)

Configuration 6 ( hide )
 cpe:/o:ntt-east:rv-s340hi_firmware
     Show Matching CPE(s)
Up to (including)
19.01.0005
Running on/with
 cpe:/h:ntt-east:rv-s340hi:-
     Show Matching CPE(s)

Configuration 7 ( hide )
 cpe:/o:ntt-east:pr-s300se_firmware
     Show Matching CPE(s)
Up to (including)
19.40
Running on/with
 cpe:/h:ntt-east:pr-s300se:-
     Show Matching CPE(s)

Configuration 8 ( hide )
 cpe:/o:ntt-east:rt-s300se_firmware
     Show Matching CPE(s)
Up to (including)
19.40
Running on/with
 cpe:/h:ntt-east:rt-s300se:-
     Show Matching CPE(s)

Configuration 9 ( hide )
 cpe:/o:ntt-east:rv-s340se_firmware
     Show Matching CPE(s)
Up to (including)
19.40
Running on/with
 cpe:/h:ntt-east:rv-s340se:-
     Show Matching CPE(s)

Configuration 10 ( hide )
 cpe:/o:ntt-east:pr-400ne_firmware
     Show Matching CPE(s)
Up to (including)
7.42
Running on/with
 cpe:/h:ntt-east:pr-400ne:-
     Show Matching CPE(s)

Configuration 11 ( hide )
 cpe:/o:ntt-east:rt-400ne_firmware
     Show Matching CPE(s)
Up to (including)
7.42
Running on/with
 cpe:/h:ntt-east:rt-400ne:-
     Show Matching CPE(s)

Configuration 12 ( hide )
 cpe:/o:ntt-east:rv-440ne_firmware
     Show Matching CPE(s)
Up to (including)
7.42
Running on/with
 cpe:/h:ntt-east:rv-440ne:-
     Show Matching CPE(s)

Configuration 13 ( hide )
 cpe:/o:ntt-east:pr-400ki_firmware
     Show Matching CPE(s)
Up to (including)
07.00.1010
Running on/with
 cpe:/h:ntt-east:pr-400ki:-
     Show Matching CPE(s)

Configuration 14 ( hide )
 cpe:/o:ntt-east:rt-400ki_firmware
     Show Matching CPE(s)
Up to (including)
07.00.1010
Running on/with
 cpe:/h:ntt-east:rt-400ki:-
     Show Matching CPE(s)

Configuration 15 ( hide )
 cpe:/o:ntt-east:rv-440ki_firmware
     Show Matching CPE(s)
Up to (including)
07.00.1010
Running on/with
 cpe:/h:ntt-east:rv-440ki:-
     Show Matching CPE(s)

Configuration 16 ( hide )
 cpe:/o:ntt-east:pr-400mi_firmware
     Show Matching CPE(s)
Up to (including)
07.00.1012
Running on/with
 cpe:/h:ntt-east:pr-400mi:-
     Show Matching CPE(s)

Configuration 17 ( hide )
 cpe:/o:ntt-east:rt-400mi_firmware
     Show Matching CPE(s)
Up to (including)
07.00.1012
Running on/with
 cpe:/h:ntt-east:rt-400mi:-
     Show Matching CPE(s)

Configuration 18 ( hide )
 cpe:/o:ntt-east:rv-440mi_firmware
     Show Matching CPE(s)
Up to (including)
07.00.1012
Running on/with
 cpe:/h:ntt-east:rv-440mi:-
     Show Matching CPE(s)

Configuration 19 ( hide )
 cpe:/o:ntt-east:pr-500ki_firmware
     Show Matching CPE(s)
Up to (including)
01.00.0090
Running on/with
 cpe:/h:ntt-east:pr-500ki:-
     Show Matching CPE(s)

Configuration 20 ( hide )
 cpe:/o:ntt-east:rt-500ki_firmware
     Show Matching CPE(s)
Up to (including)
01.00.0090
Running on/with
 cpe:/h:ntt-east:rt-500ki:-
     Show Matching CPE(s)

Configuration 21 ( hide )
 cpe:/o:ntt-east:rs-500ki_firmware
     Show Matching CPE(s)
Up to (including)
01.00.0070
Running on/with
 cpe:/h:ntt-east:rs-500ki:-
     Show Matching CPE(s)

Configuration 22 ( hide )
 cpe:/o:ntt-east:pr-500mi_firmware
     Show Matching CPE(s)
Up to (including)
01.01.0014
Running on/with
 cpe:/h:ntt-east:pr-500mi:-
     Show Matching CPE(s)

Configuration 23 ( hide )
 cpe:/o:ntt-east:rt-500mi_firmware
     Show Matching CPE(s)
Up to (including)
01.01.0014
Running on/with
 cpe:/h:ntt-east:rt-500mi:-
     Show Matching CPE(s)

Configuration 24 ( hide )
 cpe:/o:ntt-east:rs-500mi_firmware
     Show Matching CPE(s)
Up to (including)
03.01.0019
Running on/with
 cpe:/h:ntt-east:rs-500mi:-
     Show Matching CPE(s)

Configuration 25 ( hide )
 cpe:/o:ntt-west:pr-s300ne_firmware
     Show Matching CPE(s)
Up to (including)
19.41
Running on/with
 cpe:/h:ntt-west:pr-s300ne:-
     Show Matching CPE(s)

Configuration 26 ( hide )
 cpe:/o:ntt-west:rt-s300ne_firmware
     Show Matching CPE(s)
Up to (including)
19.41
Running on/with
 cpe:/h:ntt-west:rt-s300ne:-
     Show Matching CPE(s)

Configuration 27 ( hide )
 cpe:/o:ntt-west:rv-s340ne_firmware
     Show Matching CPE(s)
Up to (including)
19.41
Running on/with
 cpe:/h:ntt-west:rv-s340ne:-
     Show Matching CPE(s)

Configuration 28 ( hide )
 cpe:/o:ntt-west:pr-s300hi_firmware
     Show Matching CPE(s)
Up to (including)
19.01.0005
Running on/with
 cpe:/h:ntt-west:pr-s300hi:-
     Show Matching CPE(s)

Configuration 29 ( hide )
 cpe:/o:ntt-west:rt-s300hi_firmware
     Show Matching CPE(s)
Up to (including)
19.01.0005
Running on/with
 cpe:/h:ntt-west:rt-s300hi:-
     Show Matching CPE(s)

Configuration 30 ( hide )
 cpe:/o:ntt-west:rv-s340hi_firmware
     Show Matching CPE(s)
Up to (including)
19.01.0005
Running on/with
 cpe:/h:ntt-west:rv-s340hi:-
     Show Matching CPE(s)

Configuration 31 ( hide )
 cpe:/o:ntt-west:pr-s300se_firmware
     Show Matching CPE(s)
Up to (including)
19.40
Running on/with
 cpe:/h:ntt-west:pr-s300se:-
     Show Matching CPE(s)

Configuration 32 ( hide )
 cpe:/o:ntt-west:rt-s300se_firmware
     Show Matching CPE(s)
Up to (including)
19.40
Running on/with
 cpe:/h:ntt-west:rt-s300se:-
     Show Matching CPE(s)

Configuration 33 ( hide )
 cpe:/o:ntt-west:rv-s340se_firmware
     Show Matching CPE(s)
Up to (including)
19.40
Running on/with
 cpe:/h:ntt-west:rv-s340se:-
     Show Matching CPE(s)

Configuration 34 ( hide )
 cpe:/o:ntt-west:pr-400ne_firmware
     Show Matching CPE(s)
Up to (including)
7.42
Running on/with
 cpe:/h:ntt-west:pr-400ne:-
     Show Matching CPE(s)

Configuration 35 ( hide )
 cpe:/o:ntt-west:rt-400ne_firmware
     Show Matching CPE(s)
Up to (including)
7.42
Running on/with
 cpe:/h:ntt-west:rt-400ne:-
     Show Matching CPE(s)

Configuration 36 ( hide )
 cpe:/o:ntt-west:rv-440ne_firmware
     Show Matching CPE(s)
Up to (including)
7.42
Running on/with
 cpe:/h:ntt-west:rv-440ne:-
     Show Matching CPE(s)

Configuration 37 ( hide )
 cpe:/o:ntt-west:pr-400ki_firmware
     Show Matching CPE(s)
Up to (including)
07.00.1010
Running on/with
 cpe:/h:ntt-west:pr-400ki:-
     Show Matching CPE(s)

Configuration 38 ( hide )
 cpe:/o:ntt-west:rt-400ki_firmware
     Show Matching CPE(s)
Up to (including)
07.00.1010
Running on/with
 cpe:/h:ntt-west:rt-400ki:-
     Show Matching CPE(s)

Configuration 39 ( hide )
 cpe:/o:ntt-west:rv-440ki_firmware
     Show Matching CPE(s)
Up to (including)
07.00.1010
Running on/with
 cpe:/h:ntt-west:rv-440ki:-
     Show Matching CPE(s)

Configuration 40 ( hide )
 cpe:/o:ntt-west:pr-400mi_firmware
     Show Matching CPE(s)
Up to (including)
07.00.1012
Running on/with
 cpe:/h:ntt-west:pr-400mi:-
     Show Matching CPE(s)

Configuration 41 ( hide )
 cpe:/o:ntt-west:rt-400mi_firmware
     Show Matching CPE(s)
Up to (including)
07.00.1012
Running on/with
 cpe:/h:ntt-west:rt-400mi:-
     Show Matching CPE(s)

Configuration 42 ( hide )
 cpe:/o:ntt-west:rv-440mi_firmware
     Show Matching CPE(s)
Up to (including)
07.00.1012
Running on/with
 cpe:/h:ntt-west:rv-440mi:-
     Show Matching CPE(s)

Configuration 43 ( hide )
 cpe:/o:ntt-west:pr-500ki_firmware
     Show Matching CPE(s)
Up to (including)
01.00.0090
Running on/with
 cpe:/h:ntt-west:pr-500ki:-
     Show Matching CPE(s)

Configuration 44 ( hide )
 cpe:/o:ntt-west:rt-500ki_firmware
     Show Matching CPE(s)
Up to (including)
01.00.0090
Running on/with
 cpe:/h:ntt-west:rt-500ki:-
     Show Matching CPE(s)

Configuration 45 ( hide )
 cpe:/o:ntt-west:pr-500mi_firmware
     Show Matching CPE(s)
Up to (including)
01.01.0011
Running on/with
 cpe:/h:ntt-west:pr-500mi:-
     Show Matching CPE(s)

Configuration 46 ( hide )
 cpe:/o:ntt-west:rt-500mi_firmware
     Show Matching CPE(s)
Up to (including)
01.01.0011
Running on/with
 cpe:/h:ntt-west:rt-500mi:-
     Show Matching CPE(s)


Change History

1 change record found - show changes

Quick Info

CVE Dictionary Entry:
CVE-2019-5986
NVD Published Date:
09/12/2019
NVD Last Modified:
09/16/2019