CVE-2010-4507
Multiple cross-site request forgery (CSRF) vulnerabilities on the iSpot 2.0.0.0 R1679, and the ClearSpot 2.0.0.0 R1512 and R1786, with firmware 1.9.9.4 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary commands via the cmd parameter in an act_cmd_result action to webmain.cgi, (2) enable remote management via an enable_remote_access act_network_set action to webmain.cgi, (3) enable the TELNET service via an ENABLE_TELNET act_set_wimax_etc_config action to webmain.cgi, (4) enable TELNET sessions via a certain act_network_set action to webmain.cgi, or (5) read arbitrary files via the FILE_PATH parameter in an act_file_download action to upgrademain.cgi.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.83%
- Percentil entre todas las CVEs puntuadas: 78
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- CWE-352
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2010-4507",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2010-12-30T19:00:05.457",
"references": [
{
"url": "http://secunia.com/advisories/42590",
"source": "cve@mitre.org"
},
{
"url": "http://www.exploit-db.com/exploits/15728/",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.trustwave.com/spiderlabs/advisories/TWSL2010-008.txt",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/42590",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.exploit-db.com/exploits/15728/",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.trustwave.com/spiderlabs/advisories/TWSL2010-008.txt",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site request forgery (CSRF) vulnerabilities on the iSpot 2.0.0.0 R1679, and the ClearSpot 2.0.0.0 R1512 and R1786, with firmware 1.9.9.4 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary commands via the cmd parameter in an act_cmd_result action to webmain.cgi, (2) enable remote management via an enable_remote_access act_network_set action to webmain.cgi, (3) enable the TELNET service via an ENABLE_TELNET act_set_wimax_etc_config action to webmain.cgi, (4) enable TELNET sessions via a certain act_network_set action to webmain.cgi, or (5) read arbitrary files via the FILE_PATH parameter in an act_file_download action to upgrademain.cgi."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades de falsificación de petición en sitios cruzados (CSRF) en iSpot v2.0.0.0 R1679, y el ClearSpot v2.0.0.0 R1512 y R1786, con firmware v1.9.9.4, permite a atacantes remotos secuestrar la autenticación de los usuarios por peticiones que (1) ejecuten comandos de su elección a través del parámetro cmd en una acción act_cmd_result sobre webmain.cgi, (2) permitir la gestión remota a través de una acción enable_remote_access act_network_set sobre webmain.cgi, (3) permitir el servicio TELNET a través de una acción ENABLE_TELNET act_set_wimax_etc_config sobre webmain.cgi, (4) disponer sesiones TELNET a través de ciertas acciones act_network_set sobre webmain.cgi, o (5) leer ficheros de su elección a través del parámetro FILE_PATH en una acción act_file_download sobre upgrademain.cgi."
}
],
"lastModified": "2026-06-16T23:24:56.587",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:clear:ispot_firmware:1.9.9.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "18AEED9D-F7C0-4C14-BDC7-3E144DEBDB9F"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:clear:ispot:2.0.0.0:r1679:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CC710D6D-20E9-469B-A3D5-E5942D7FE299"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:clear:clearspot_firmware:1.9.9.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "70383CFF-6605-47D5-B7DC-8BB172185C7B"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:clear:clearspot:2.0.0.0:r1512:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2D1B3013-ACA9-4976-BF2A-65B1FB2817AF"
},
{
"criteria": "cpe:2.3:h:clear:clearspot:2.0.0.0:r1786:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7E7E21CE-F424-4A9B-A9F7-99A85D34B76C"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}