vendor:
EW-7438RPn
by:
Besim ALTINOK
8.8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: EW-7438RPn
Affected Version From: 1.13
Affected Version To: 1.13
Patch Exists: YES
Related CWE: N/A
CPE: h:edimax:ew-7438rpn_mini
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Edimax EW-7438RPn 1.13 Version
2020
Edimax EW-7438RPn – Cross-Site Request Forgery (MAC Filtering)
A Cross-Site Request Forgery (CSRF) vulnerability exists in Edimax EW-7438RPn 1.13 Version, which allows an attacker to add a new MAC address to the MAC filtering list. An attacker can craft a malicious HTML page and send it to the victim, when the victim visits the malicious page, the attacker can add a new MAC address to the MAC filtering list.
Mitigation:
The vendor recommends users to upgrade to the latest version of the firmware.