CVE-2008-6605
Estado: ModificadaMedia (6.8)—
Cross-site request forgery (CSRF) vulnerability in the xslt script in the web-based management interface on the 2wire 1701HG, 1800HW, 2071HG, and 2700HG with firmware 3.17.5, 3.7.1, 4.25.19, or 5.29.51 allows remote attackers to hijack the intranet connectivity of arbitrary users for requests that cause a denial of service (network outage) via a page parameter with a % (percent) character followed by a non-alphanumeric character.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.94%
- Percentil entre todas las CVEs puntuadas: 59
- Fecha de la puntuación: 2/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- CWE-352
Referencias
- http://osvdb.org/49835
- http://www.securityfocus.com/bid/32211
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46537
- https://www.exploit-db.com/exploits/7060
- http://osvdb.org/49835
- http://www.securityfocus.com/bid/32211
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46537
- https://www.exploit-db.com/exploits/7060
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-6605",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-04-06T14:30:00.250",
"references": [
{
"url": "http://osvdb.org/49835",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/32211",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46537",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/7060",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/49835",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/32211",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46537",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/7060",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cross-site request forgery (CSRF) vulnerability in the xslt script in the web-based management interface on the 2wire 1701HG, 1800HW, 2071HG, and 2700HG with firmware 3.17.5, 3.7.1, 4.25.19, or 5.29.51 allows remote attackers to hijack the intranet connectivity of arbitrary users for requests that cause a denial of service (network outage) via a page parameter with a % (percent) character followed by a non-alphanumeric character."
},
{
"lang": "es",
"value": "Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en la secuencia de comandos (script) xslt en la interfaz de gestión basada en web en 2wire 1701HG, 1800HW, 2071HG, y 2700HG con software empotrado (firmware) 3.17.5, 3.7.1, 4.25.19, o 5.29.51 permite a atacantes remotos secuestrar la conectividad de la intranet de usuarios de su elección para peticiones que provocan una denegación de servicio (corte de red) a través del parámetro \"page\" con un carácter % (por ciento) permitido por un carácter no alfanumérico."
}
],
"lastModified": "2026-06-16T23:02:33.510",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:2wire:1701hg:3.7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A9E57A4E-6027-4746-B448-EBE314204195"
},
{
"criteria": "cpe:2.3:h:2wire:1701hg:3.17.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B41E413-BFE7-489A-AEEF-EE4E2A1C3400"
},
{
"criteria": "cpe:2.3:h:2wire:1701hg:4.25.19:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A5D67397-9203-4F77-9BEB-99488BD04986"
},
{
"criteria": "cpe:2.3:h:2wire:1701hg:5.29.51:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD8AE2D3-B32F-488E-BF2F-C1FF48888EA3"
},
{
"criteria": "cpe:2.3:h:2wire:1800hw:3.7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B6E391DE-3C16-4184-9539-727E4514495F"
},
{
"criteria": "cpe:2.3:h:2wire:1800hw:3.17.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AB3507B7-2244-4474-A778-F2DE99892FF2"
},
{
"criteria": "cpe:2.3:h:2wire:1800hw:4.25.19:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "608EDD3A-D9BD-4A52-B574-022D557D19BF"
},
{
"criteria": "cpe:2.3:h:2wire:1800hw:5.29.51:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0559DC0E-3AC8-4BF4-BE42-18BBAB0A01DA"
},
{
"criteria": "cpe:2.3:h:2wire:2071hg:3.7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8CA2383F-F4ED-4E15-BCF3-147FFB1AB9E2"
},
{
"criteria": "cpe:2.3:h:2wire:2071hg:3.17.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D76D05D1-7C09-44B0-9CF1-2AF4481C9B08"
},
{
"criteria": "cpe:2.3:h:2wire:2071hg:4.25.19:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7F0131C7-4B6F-4E70-9302-8086C68608C2"
},
{
"criteria": "cpe:2.3:h:2wire:2071hg:5.29.51:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CBBF27FB-74F1-4BD4-8E47-86DB966C46EB"
},
{
"criteria": "cpe:2.3:h:2wire:2700hg:3.7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A891B7D4-1949-474C-91AD-CBC606C0C742"
},
{
"criteria": "cpe:2.3:h:2wire:2700hg:3.17.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E781C116-7C24-4B47-A552-2153E2E3636D"
},
{
"criteria": "cpe:2.3:h:2wire:2700hg:4.25.19:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D3BE0B7E-4DFE-42BC-BA1B-0CA7931288A6"
},
{
"criteria": "cpe:2.3:h:2wire:2700hg:5.29.51:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9950F2F2-3808-4181-B942-2166EBE3C6F6"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}