vendor:
TP-LINK Admin Panel
by:
Juan Manuel Garcia
4
CVSS
MEDIUM
Cross Site Request Forgery (CSRF)
CWE
Product Name: TP-LINK Admin Panel
Affected Version From: Firmware v3.13.6 Build 110923 Rel.53137n
Affected Version To: other versions may also be affected
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: WR2543ND or any running the vulnerable firmware
2013
Multiple Cross Site Request Forgery vulnerabilities in TP-LINK Admin Panel
Multiple Cross Site Request Forgery vulnerabilities were found in TP-LINK Admin Panel, because the application allows authorized users to perform certain actions via HTTP requests without making proper validity checks to verify the source of the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.