vendor:
Nexus 543 IP Camera
by:
Independent Security Researcher
7,5
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Nexus 543 IP Camera
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2013-3311
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
Loftek Nexus 543 CSRF PoC
This exploit allows an attacker to reset the admin password of a Loftek Nexus 543 IP camera by sending a maliciously crafted HTTP request. This exploit was discovered by an independent security researcher in 2013 and was assigned CVE-2013-3311.
Mitigation:
The best way to mitigate CSRF attacks is to use a combination of security measures such as same-site cookies, anti-CSRF tokens, and origin header checks.