header-logo
Suggest Exploit
vendor:
Gate2 Plus Wi-Fi
by:
SecurityFocus
7.5
CVSS
HIGH
Cross-Site Request-Forgery
352
CWE
Product Name: Gate2 Plus Wi-Fi
Affected Version From: Alice Gate2 Plus Wi-Fi router firmware
Affected Version To: Alice Gate2 Plus Wi-Fi router firmware
Patch Exists: YES
Related CWE: N/A
CPE: h:alice:gate2_plus_wifi
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Alice Gate2 Plus Wi-Fi Cross-Site Request-Forgery Vulnerability

Alice Gate2 Plus Wi-Fi routers are prone to a cross-site request-forgery vulnerability. An attacker can exploit this issue to alter administrative configuration on affected devices. Specifically, altering the wireless encryption settings on devices has been demonstrated. Other attacks may also be possible.

Mitigation:

Administrators should ensure that they are running the latest version of the Alice Gate2 Plus Wi-Fi router firmware. Additionally, administrators should ensure that they are using strong passwords for administrative accounts.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/27374/info

Alice Gate2 Plus Wi-Fi routers are prone to a cross-site request-forgery vulnerability.

An attacker can exploit this issue to alter administrative configuration on affected devices. Specifically, altering the wireless encryption settings on devices has been demonstrated. Other attacks may also be possible. 

http://www.example.com/cp06_wifi_m_nocifr.cgi?wlChannel=Auto&wlRadioEnable=on