PT-2009-2292 · A Link · A-Link Wl54Ap2+1

Henri Lindberg

+1

·

Publicado

2009-06-04

·

Atualizado

2018-10-11

·

CVE-2008-6823

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: A-LINK WL54AP3 versions prior to 1.4.2-eng1 A-LINK WL54AP2 versions prior to 1.4.2-eng1
Description: The issue concerns multiple cross-site request forgery (CSRF) vulnerabilities in the management interface of the affected access points. These vulnerabilities allow remote attackers to hijack the authentication of administrators for specific requests. The requests in question can modify the network configuration via certain parameters to "goform/formWanTcpipSetup" or modify credentials via certain parameters to "goform/formPasswordSetup".
Recommendations: For A-LINK WL54AP3 versions prior to 1.4.2-eng1, update to firmware version 1.4.2-eng1 or later. For A-LINK WL54AP2 versions prior to 1.4.2-eng1, update to firmware version 1.4.2-eng1 or later. As a temporary workaround, consider restricting access to the management interface to minimize the risk of exploitation. Avoid using the vulnerable parameters in the affected API endpoints until the issue is resolved.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-6823

Produtos afetados

A-Link Wl54Ap2
A-Link Wl54Ap3