PT-2018-4012 · Draytek · Draytek Vigor
Publicado
2018-05-18
·
Atualizado
2020-04-03
·
CVE-2018-20872
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
DrayTek routers versions prior to 2018-05-23
Description
The issue is related to a CSRF attack that can change DNS or DHCP settings. It is associated with a flaw in the web interface of DrayTek Vigor router firmware, allowing a remote attacker to perform a CSRF attack.
Recommendations
For versions prior to 2018-05-23, update the firmware to a version released after 2018-05-23 to resolve the issue. As a temporary workaround, consider restricting access to the web interface to minimize the risk of exploitation.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Draytek Vigor