vendor:
Smart Inter@ctive 3.0
by:
Ahmethan-Gultekin - t4rkd3vilz
8.8
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: Smart Inter@ctive 3.0
Affected Version From: Smart Inter@ctive 3.0
Affected Version To: Smart Inter@ctive 3.0
Patch Exists: YES
Related CWE: CVE-2018-13989
CPE: a:grundig:smart_inter@ctive_3.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2018
Grundig Smart Inter@ctive 3.0 – Cross-Site Request Forgery
Ahmethan-Gultekin - t4rkd3vilz discovered a Cross-Site Request Forgery vulnerability in Grundig Smart Inter@ctive 3.0. The vulnerability allowed an attacker to send malicious requests to the application from a computer with the same IP address as the TV and the phone. The attacker could then gain access to the interface from the 8085 port.
Mitigation:
Developers should ensure that all user-supplied input is properly validated and sanitized. Additionally, developers should ensure that all requests are sent over a secure connection.