CVE-2014-8654 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 2.9% (pctl 86)
Patch early
A public exploit exists.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway hardware 1.0 with firmware CH6640-3.5.11.7-NOSH allow remote attackers to hijack the authentication of administrators for requests that (1) have unspecified impact on DDNS configuration via a request to basicDDNS.html, (2) change the wifi password via the psKey parameter to setWirelessSecurity.html, (3) add a static MAC address via the MacAddress parameter in an add_static action to setBasicDHCP1.html, or (4) enable or disable UPnP via the UPnP parameter in an apply action to setAdvancedOptions.html.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 2.87% — more likely to be exploited than 86% of all CVEs |
| Weakness | CWE-352 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-11-06 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| compal broadband networks | cg6640e wireless gateway |
| compal broadband networks | ch664oe wireless gateway |
| compal broadband networks | firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | CBN CH6640E/CG6640E Wireless Gateway Series - Multiple Vulnerabilities | 2014-10-27 |
References
- http://osvdb.org/show/osvdb/113840
- http://osvdb.org/show/osvdb/113841
- http://osvdb.org/show/osvdb/113842
- http://osvdb.org/show/osvdb/113843
- http://packetstormsecurity.com/files/128860/CBN-CH6640E-CG6640E-Wireless-Gateway-XSS-CSRF-DoS-Disclosure.html
- http://www.exploit-db.com/exploits/35075
- http://www.securityfocus.com/bid/70762
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2014-5203.php
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98329
- http://osvdb.org/show/osvdb/113840
- http://osvdb.org/show/osvdb/113841
- http://osvdb.org/show/osvdb/113842
- http://osvdb.org/show/osvdb/113843
- http://packetstormsecurity.com/files/128860/CBN-CH6640E-CG6640E-Wireless-Gateway-XSS-CSRF-DoS-Disclosure.html
- http://www.exploit-db.com/exploits/35075
- http://www.securityfocus.com/bid/70762
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2014-5203.php
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98329
→ the Explorer · watch your stack · NVD