Description
Teradek Cube 7.3.6 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft a malicious web page with a hidden form to submit password change requests to the device's system configuration interface.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
7.3.15
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5464.php
www.exploit-db.com/exploits/44675 (ExploitDB-44675)
www.teradek.com (Teradek Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5464.php (Zero Science Lab Disclosure (ZSL-2018-5464))
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.