Vulnerabilities > Kddi > Home Spot Cube Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2016-01-30 CVE-2016-1139 Cross-Site Request Forgery (CSRF) vulnerability in Kddi Home Spot Cube Firmware 2.0
Cross-site request forgery (CSRF) vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
network
high complexity
kddi CWE-352
7.5
2016-01-30 CVE-2016-1137 Unspecified vulnerability in Kddi Home Spot Cube Firmware 2.0
Open redirect vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
network
low complexity
kddi
7.4