PT-2018-5333 · Draytek · Draytek Vigor Ap910C

Publicado

2018-03-06

·

Atualizado

2021-06-03

·

CVE-2017-11649

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DrayTek Vigor AP910C version 1.2.0 RC3 build r6594
Description A cross-site request forgery issue allows remote attackers to hijack user authentication for requests that enable SNMP on the device. This is achieved via vectors involving the "goform/setSnmp" endpoint.
Recommendations For DrayTek Vigor AP910C version 1.2.0 RC3 build r6594, consider disabling the goform/setSnmp endpoint until a patch is available to prevent exploitation. Restrict access to the SNMP configuration to minimize the risk of unauthorized changes.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-11649

Produtos afetados

Draytek Vigor Ap910C