vendor:
TEM Opera Plus FM Family Transmitter
by:
Gjoko 'LiquidWorm' Krstic
7.1
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: TEM Opera Plus FM Family Transmitter
Affected Version From: 35.45
Affected Version To: 35.45
Patch Exists: NO
Related CWE: CVE-2023-XXXX (yet to be assigned)
CPE: h:tem:opera_plus_fm_transmitter:35.45
Platforms Tested: Webserver
2023
TEM Opera Plus FM Family Transmitter 35.45 XSRF Vulnerability
The TEM Opera Plus FM Family Transmitter 35.45 devices are vulnerable to Cross-Site Request Forgery (CSRF) attacks due to lack of proper validation of HTTP requests. An attacker can exploit this vulnerability to perform malicious actions with administrative privileges if a logged-in user visits a specially crafted website. This can lead to unauthorized changes in transmitter settings, such as forward power, frequency, and user credentials.
Mitigation:
To mitigate this vulnerability, users are advised to implement proper validation mechanisms for HTTP requests, such as anti-CSRF tokens. It is recommended to avoid clicking on untrusted links or visiting malicious websites while authenticated into the TEM Opera Plus FM Family Transmitter 35.45 devices.