vendor:
Tripmate HT-TM01
by:
Ken Smith
N/A
CVSS
N/A
Cross Site Request Forgery
352
CWE
Product Name: Tripmate HT-TM01
Affected Version From: HT-TM01, version 2.000.022
Affected Version To: HT-TM01, version 2.000.022
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
HooToo Tripmate HT-TM01 Cross Site Request Forgery
Various functions in the device's admin web portal are vulnerable to Cross Site Request Forgery. Proof-of-concept HTML has been provided. In order for changes in wireless settings/security (executed via CSRF) to apply, a save and reset must be execute either by the admin manually saving the settings through the portal or via the save and reset CSRF-vulnerable functions described below.
Mitigation:
No solution is currently available.