vendor:
NAT32
by:
hyp3rlinx
8.8
CVSS
HIGH
Remote Command Execution (CSRF)
352
CWE
Product Name: NAT32
Affected Version From: NAT32 Build (22284)
Affected Version To: NAT32 Build (22284)
Patch Exists: NO
Related CWE: CVE-2018-6941
CPE: NAT32
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WIN32
2018
NAT32-REMOTE-COMMAND-EXECUTION-CSRF-CVE-2018-6941
CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution. Remote attackers can potentially execute arbitrary System Commands due to a Cross Site Request Forgery, if an authenticated NAT32 user clicks a malicious link or visits an attacker controlled webpage as NAT32 performs no check for blind requests.
Mitigation:
Vendor has removed the HTTPD code from Build 22284 of NAT32