CVE-2014-2946
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 1.1%
from disclosure to weapon0 days
Published on NVDJun 2
1st PoCMay 30
exploitation probability
1.1%top 38% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Cross-site request forgery (CSRF) vulnerability in api/sms/send-sms in the Web UI 11.010.06.01.858 on Huawei E303 modems with software 22.157.18.00.858 allows remote attackers to hijack the authentication of administrators for requests that perform API operations and send SMS messages via a request element in an XML document.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/39209⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.