CVE-2019-5986

HIGHCVSS 8.8/10EPSS 0.78%

Last modified

CVE-2019-5986 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Cross-site request forgery (CSRF) vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firmware version Ver. 19.41 and earlier, PR-S300HI/RT-S300HI/RV-S340HI firmware version Ver.19.01.0005 and earlier, PR-S300SE/RT-S300SE/RV-S340SE firmware version Ver.19.40 and earlier, PR-400NE/RT-400NE/RV-440NE firmware version Ver.7.42 and earlier, PR-400KI/RT-400KI/RV-440KI firmware version Ver.07.00.1010 and earlier, PR-400MI/RT-400MI/RV-440MI firmware version Ver. EPSS estimates a 0.78% chance of exploitation in the next 30 days.

Description

Cross-site request forgery (CSRF) vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firmware version Ver. 19.41 and earlier, PR-S300HI/RT-S300HI/RV-S340HI firmware version Ver.19.01.0005 and earlier, PR-S300SE/RT-S300SE/RV-S340SE firmware version Ver.19.40 and earlier, PR-400NE/RT-400NE/RV-440NE firmware version Ver.7.42 and earlier, PR-400KI/RT-400KI/RV-440KI firmware version Ver.07.00.1010 and earlier, PR-400MI/RT-400MI/RV-440MI firmware version Ver. 07.00.1012 and earlier, PR-500KI/RT-500KI firmware version Ver.01.00.0090 and earlier, RS-500KI firmware version Ver.01.00.0070 and earlier, PR-500MI/RT-500MI firmware version Ver.01.01.0014 and earlier, and RS-500MI firmware version Ver.03.01.0019 and earlier, and Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firmware version Ver. 19.41 and earlier, PR-S300HI/RT-S300HI/RV-S340HI firmware version Ver.19.01.0005 and earlier, PR-S300SE/RT-S300SE/RV-S340SE firmware version Ver.19.40 and earlier, PR-400NE/RT-400NE/RV-440NE firmware version Ver.7.42 and earlier, PR-400KI/RT-400KI/RV-440KI firmware version Ver.07.00.1010 and earlier, PR-400MI/RT-400MI/RV-440MI firmware version Ver. 07.00.1012 and earlier, PR-500KI/RT-500KI firmware version Ver.01.00.0090 and earlier, and PR-500MI/RT-500MI firmware version Ver.01.01.0011 and earlier) allow remote attackers to hijack the authentication of administrators via unspecified vectors.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Probability
0.78%

51.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Ntt-EastPr-S300ne Firmware<= 19.41
Ntt-EastRt-S300ne Firmware<= 19.41
Ntt-EastRv-S340ne Firmware<= 19.41
Ntt-EastPr-S300hi Firmware<= 19.01.0005
Ntt-EastRt-S300hi Firmware<= 19.01.0005
Ntt-EastRv-S340hi Firmware<= 19.01.0005
Ntt-EastPr-S300se Firmware<= 19.40
Ntt-EastRt-S300se Firmware<= 19.40
Ntt-EastRv-S340se Firmware<= 19.40
Ntt-EastPr-400ne Firmware<= 7.42
Ntt-EastRt-400ne Firmware<= 7.42
Ntt-EastRv-440ne Firmware<= 7.42
Ntt-EastPr-400ki Firmware<= 07.00.1010
Ntt-EastRt-400ki Firmware<= 07.00.1010
Ntt-EastRv-440ki Firmware<= 07.00.1010
Ntt-EastPr-400mi Firmware<= 07.00.1012
Ntt-EastRt-400mi Firmware<= 07.00.1012
Ntt-EastRv-440mi Firmware<= 07.00.1012
Ntt-EastPr-500ki Firmware<= 01.00.0090
Ntt-EastRt-500ki Firmware<= 01.00.0090
Ntt-EastRs-500ki Firmware<= 01.00.0070
Ntt-EastPr-500mi Firmware<= 01.01.0014
Ntt-EastRt-500mi Firmware<= 01.01.0014
Ntt-EastRs-500mi Firmware<= 03.01.0019
Ntt-WestPr-S300ne Firmware<= 19.41
Ntt-WestRt-S300ne Firmware<= 19.41
Ntt-WestRv-S340ne Firmware<= 19.41
Ntt-WestPr-S300hi Firmware<= 19.01.0005
Ntt-WestRt-S300hi Firmware<= 19.01.0005
Ntt-WestRv-S340hi Firmware<= 19.01.0005
Ntt-WestPr-S300se Firmware<= 19.40
Ntt-WestRt-S300se Firmware<= 19.40
Ntt-WestRv-S340se Firmware<= 19.40
Ntt-WestPr-400ne Firmware<= 7.42
Ntt-WestRt-400ne Firmware<= 7.42
Ntt-WestRv-440ne Firmware<= 7.42
Ntt-WestPr-400ki Firmware<= 07.00.1010
Ntt-WestRt-400ki Firmware<= 07.00.1010
Ntt-WestRv-440ki Firmware<= 07.00.1010
Ntt-WestPr-400mi Firmware<= 07.00.1012
Ntt-WestRt-400mi Firmware<= 07.00.1012
Ntt-WestRv-440mi Firmware<= 07.00.1012
Ntt-WestPr-500ki Firmware<= 01.00.0090
Ntt-WestRt-500ki Firmware<= 01.00.0090
Ntt-WestPr-500mi Firmware<= 01.01.0011
Ntt-WestRt-500mi Firmware<= 01.01.0011

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-5986?
Cross-site request forgery (CSRF) vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firmware version Ver. 19.41 and earlier, PR-S300HI/RT-S300HI/RV-S340HI firmware version Ver.19.01.0005 and earlier, PR-S300SE/RT-S300SE/RV-S340SE firmware version Ver.19.40 and earlier, PR-400NE/RT-400NE/RV-440NE firmware version Ver.7.42 and earlier, PR-400KI/RT-400KI/RV-440KI firmware version Ver.07.00.1010 and earlier, PR-400MI/RT-400MI/RV-440MI firmware version Ver. 07.00.1012 and earlier, PR-500KI/RT-500KI firmware version Ver.01.00.0090 and earlier, RS-500KI firmware version Ver.01.00.0070 and earlier, PR-500MI/RT-500MI firmware version Ver.01.01.0014 and earlier, and RS-500MI firmware version Ver.03.01.0019 and earlier, and Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firmware version Ver. 19.41 and earlier, PR-S300HI/RT-S300HI/RV-S340HI firmware version Ver.19.01.0005 and earlier, PR-S300SE/RT-S300SE/RV-S340SE firmware version Ver.19.40 and earlier, PR-400NE/RT-400NE/RV-440NE firmware version Ver.7.42 and earlier, PR-400KI/RT-400KI/RV-440KI firmware version Ver.07.00.1010 and earlier, PR-400MI/RT-400MI/RV-440MI firmware version Ver. 07.00.1012 and earlier, PR-500KI/RT-500KI firmware version Ver.01.00.0090 and earlier, and PR-500MI/RT-500MI firmware version Ver.01.01.0011 and earlier) allow remote attackers to hijack the authentication of administrators via unspecified vectors.
How severe is CVE-2019-5986?
CVE-2019-5986 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.78% probability of exploitation in the next 30 days.
How do I fix CVE-2019-5986?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-5986?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST