vendor:
Sunny WebBox
by:
Borja Merino and Eduardo Villaverde
8.8
CVSS
HIGH
Cross-Site Request Forgery
CSRF
CWE
Product Name: Sunny WebBox
Affected Version From: Firmware Version 1.6 and prior
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2019-13529
CPE: a:sma:sunny_webbox_firmware:1.6
Platforms Tested: Sunny WebBox SMA Solar Device (Firmware Version 1.6)
2019
SMA Solar Technology AG Sunny WebBox device – 1.6 – Cross-Site Request Forgery
This exploit allows an attacker to perform unauthorized actions on the SMA Solar Technology AG Sunny WebBox device by tricking a logged-in user into submitting a malicious form. The exploit takes advantage of a lack of CSRF protection in the device's firmware version 1.6 and prior.
Mitigation:
To mitigate this vulnerability, users should update the firmware of the Sunny WebBox device to a version that includes CSRF protection. Users should also be cautious of clicking on links or submitting forms from untrusted sources.