vendor:
KYOCERA Net Admin
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: KYOCERA Net Admin
Affected Version From: 3.4.0906
Affected Version To: 3.4.0906
Patch Exists: NO
Related CWE:
CPE: a:kyocera:net_admin:3.4.0906
Platforms Tested: Microsoft Windows 7 Professional SP1 (EN)
2018
KYOCERA Net Admin 3.4 CSRF Add Admin Exploit
The KYOCERA Net Admin 3.4 application allows users to perform actions via HTTP requests without performing validity checks. This can be exploited to perform actions with administrative privileges if a logged-in user visits a malicious website.
Mitigation:
Implement proper input validation and verification of HTTP requests. Apply security patches and updates.