vendor:
Gate2 Plus Wi-Fi
by:
SecurityFocus
7.5
CVSS
HIGH
Cross-Site Request-Forgery
352
CWE
Product Name: Gate2 Plus Wi-Fi
Affected Version From: Alice Gate2 Plus Wi-Fi router firmware
Affected Version To: Alice Gate2 Plus Wi-Fi router firmware
Patch Exists: YES
Related CWE: N/A
CPE: h:alice:gate2_plus_wifi
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Alice Gate2 Plus Wi-Fi Cross-Site Request-Forgery Vulnerability
Alice Gate2 Plus Wi-Fi routers are prone to a cross-site request-forgery vulnerability. An attacker can exploit this issue to alter administrative configuration on affected devices. Specifically, altering the wireless encryption settings on devices has been demonstrated. Other attacks may also be possible.
Mitigation:
Administrators should ensure that they are running the latest version of the Alice Gate2 Plus Wi-Fi router firmware. Additionally, administrators should ensure that they are using strong passwords for administrative accounts.