Vulnerabilities > CVE-2014-9143 - Code vulnerability in Technicolor Td5130 Router Firmware 2.05.C29Gv

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
technicolor
CWE-17
exploit available

Summary

Open redirect vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the failrefer parameter.

Vulnerable Configurations

Part Description Count
OS
Technicolor
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionTechnicolor DT5130 2.05.C29GV - Multiple Vulnerabilities. CVE-2014-9142,CVE-2014-9143,CVE-2014-9144. Webapps exploit for hardware platform
fileexploits/hardware/webapps/35462.txt
idEDB-ID:35462
last seen2016-02-04
modified2014-12-04
platformhardware
port80
published2014-12-04
reporterCrash
sourcehttps://www.exploit-db.com/download/35462/
titleTechnicolor DT5130 2.05.C29GV - Multiple Vulnerabilities
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/129374/adsl2plus-xssredirectinject.txt
idPACKETSTORM:129374
last seen2016-12-05
published2014-12-03
reporterEwerson Guimaraes
sourcehttps://packetstormsecurity.com/files/129374/ADSL2-2.05.C29GV-XSS-URL-Redirect-Command-Injection.html
titleADSL2+ 2.05.C29GV XSS / URL Redirect / Command Injection