CVE-2013-7043 describes multiple Cross-Site Request Forgery (CSRF) vulnerabilities affecting Cisco Scientific Atlanta DPR2320R2 routers with specific software versions. These flaws allow remote attackers to hijack authenticated administrator sessions to perform actions such as changing passwords, rebooting the device, or modifying Wi-Fi and parental control settings. With a CVSS score of 8.3 (High), the vulnerability is remotely exploitable with medium attack complexity and no authentication required, leading to potential partial confidentiality, partial integrity, and complete availability impacts. The FAUCET Risk Score is 90/100, indicating a significant risk. While there is an ExploitDB entry (EDB-29927) detailing the CSRF vulnerabilities, there is no evidence of active exploitation (not in KEV), nor are there Metasploit or Nuclei modules. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.2CPE matchmatch criteria | cpe:2.3:o:cisco:scientific_atlanta__dpr\/epr2320_firmware:2.0.2:r1262-090417:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:cisco:scientific_atlanta__dpr\/epr2320:-:*:*:*:*:*:*:* | ||
2.0.2CPE matchmatch criteria | cpe:2.3:o:cisco:scientific_atlanta__dpr2325_firmware:2.0.2:r1262-090417:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:cisco:scientific_atlanta__dpr2325:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.