Overview
The Phillipine Long Distance Telephone (PLDT) company provides internet access in the Phillippines. The SpeedSurf 504AN and Kasda KW58293 modems distributed by PLDT contain multiple vulnerabilities. The BaudTec ADSL2+ Router may also be affected.
Description
| PLDT provides SpeedSurf 504AN, firmware version GAN9.8U26-4-TX-R6B018-PH.EN, and the Kasda KW58293, to customers for internet access. These devices contains multiple vulnerabilities. CWE-352: Cross-Site Request Forgery (CSRF) - CVE-2015-5991 | 
Impact
| A remote attacker may utilize these credentials to gain administrator access to the device. A remote attacker may also be able to cause a denial of service. | 
Solution
| The CERT/CC is currently unaware of a practical solution to this problem. | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | 7.4 | AV:A/AC:M/Au:S/C:C/I:C/A:C | 
| Temporal | 6.3 | E:POC/RL:U/RC:UR | 
| Environmental | 4.7 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND | 
References
Acknowledgements
Thanks to Eskie Cirrus James Maquilang for reporting this vulnerability to us.
This document was written by Garret Wassermann.
Other Information
| CVE IDs: | CVE-2015-5991, CVE-2015-5992, CVE-2015-5993 | 
| Date Public: | 2015-08-31 | 
| Date First Published: | 2015-08-31 | 
| Date Last Updated: | 2016-04-17 23:16 UTC | 
| Document Revision: | 52 |