vendor:
Platinum-4410
by:
Jinson Varghese Behanan
6.5
CVSS
MEDIUM
Broken Access Control and CSRF
284
CWE
Product Name: Platinum-4410
Affected Version From: v2.1 (software version P4410-V2-1.28)
Affected Version To: v2.1 (software version P4410-V2-1.28)
Patch Exists: NO
Related CWE: CVE-2020-25015
CPE: h:genexis:platinum-4410
Platforms Tested:
2020
Genexis Platinum-4410 P4410-V2-1.28 – Broken Access Control and CSRF
Platinum 4410 router from Genexis with hardware version V2.1 and software version P4410-V2-1.28 is vulnerable to Broken Access Control and CSRF. This vulnerability allows an attacker to remotely change the WIFI access point's password by sending a specially crafted link to the victim while they are connected to the vulnerable router's WiFi network.
Mitigation:
The vendor has not provided a patch for this vulnerability. Users are advised to update to the latest firmware version or consider replacing the affected router with a more secure alternative.