Improper Restriction of Rendered UI Layers or Frames in IR615 Router - CVE-2021-38472
Published: October 8, 2021
Vulnerability identifier: #VU57151
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-38472
CWE-ID: CWE-1021
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
IR615 Router
IR615 Router
Software vendor:
InHand Networks
InHand Networks
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the management portal does not contain an X-FRAME-OPTIONS header. A remote attacker can send a link to an administrator that frames the router’s management portal and lure the administrator to perform changes.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.