vendor:
Intelbras Router WRN150
by:
Prof. Joas Antonio
5.5
CVSS
MEDIUM
Cross-Site Request Forgery
352
CWE
Product Name: Intelbras Router WRN150
Affected Version From: 1.0.18
Affected Version To: 1.0.18
Patch Exists: NO
Related CWE:
CPE: a:intelbras:router_wrn150:1.0.18
Platforms Tested: Windows
2019
Intelbras Router WRN150 1.0.18 – Cross-Site Request Forgery
The Intelbras Router WRN150 version 1.0.18 is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can trick a user into submitting a malicious form that changes the system password without their knowledge or consent.
Mitigation:
To mitigate this vulnerability, Intelbras should implement and enforce the use of anti-CSRF tokens in their web application to validate the origin of requests.