vendor:
WLM-2501
by:
Ivano Binetti
8,8
CVSS
HIGH
CSRF
352
CWE
Product Name: WLM-2501
Affected Version From: WLM-2501
Affected Version To: WLM-2501
Patch Exists: NO
Related CWE: N/A
CPE: h:sitecom:wlm-2501
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: All Sitecom WL series might be is affected by these vulnerabilities
2012
Sitecom WLM-2501 new Multiple CSRF Vulnerabilities
The web interface of this router is affected by muktiple CSRF vulnerabilities which allows to change the following router's parameters: Disable Mac Filtering, Disable/Modify IP/Port Filtering, Disable/Modify Port Forwarding, Disable/Modify Wireless Access Control, Disable Wi-Fi Protected Setup, Disable/Modify URL Blocking Filter, Disable/Modify Domain Blocking Filter, Disable/Modify IP Address ACL, Change Wireless Passphrase, Enable/Modify Remote Access (also on WAN interface)
Mitigation:
Ensure that all web applications are properly validated and sanitized to prevent CSRF attacks.