High severity8.8NVD Advisory· Published Sep 11, 2017· Updated May 13, 2026
CVE-2017-14267
CVE-2017-14267
Description
EE 4GEE WiFi MBB (before EE60_00_05.00_31) devices have CSRF, related to goform/AddNewProfile, goform/setWanDisconnect, goform/setSMSAutoRedirectSetting, goform/setReset, and goform/uploadBackupSettings.
Affected products
1- cpe:2.3:o:ee:4gee_wifi_mbb_firmware:*:*:*:*:*:*:*:*Range: <=ee60_00_05.00_25
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- seclists.org/fulldisclosure/2017/Sep/13nvdExploitMailing ListThird Party Advisory
- blog.jameshemmings.co.uk/2017/08/24/ee-4gee-mobile-wifi-router-multiple-security-vulnerabilities-writeupnvdExploitThird Party Advisory
- github.com/JamesIT/vuln-advisories-/blob/master/EE-4GEE-Multiple-Vulns/CSRF/AddProfileCSRFXSSPoc.htmlnvdExploitThird Party Advisory
- github.com/JamesIT/vuln-advisories-/blob/master/EE-4GEE-Multiple-Vulns/CSRF/CSRFInternetDCPoC.htmlnvdExploitThird Party Advisory
- github.com/JamesIT/vuln-advisories-/blob/master/EE-4GEE-Multiple-Vulns/CSRF/CSRFPocRedirectSMS.htmlnvdExploitThird Party Advisory
- github.com/JamesIT/vuln-advisories-/blob/master/EE-4GEE-Multiple-Vulns/CSRF/CSRFPocResetDefaults.htmlnvdExploitThird Party Advisory
- github.com/JamesIT/vuln-advisories-/blob/master/EE-4GEE-Multiple-Vulns/CSRF/uploadBinarySettingsCSRFPoC.htmlnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.