Improper Restriction of Rendered UI Layers or Frames in IR615 Router - CVE-2021-38472

 

Improper Restriction of Rendered UI Layers or Frames in IR615 Router - CVE-2021-38472

Published: October 8, 2021


Vulnerability identifier: #VU57151
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-38472
CWE-ID: CWE-1021
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
IR615 Router
Software vendor:
InHand Networks

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the management portal does not contain an X-FRAME-OPTIONS header. A remote attacker can send a link to an administrator that frames the router’s management portal and lure the administrator to perform changes. 


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links