PT-2018-5333 · Draytek · Draytek Vigor Ap910C
Publicado
2018-03-06
·
Atualizado
2021-06-03
·
CVE-2017-11649
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DrayTek Vigor AP910C version 1.2.0 RC3 build r6594
Description
A cross-site request forgery issue allows remote attackers to hijack user authentication for requests that enable SNMP on the device. This is achieved via vectors involving the "goform/setSnmp" endpoint.
Recommendations
For DrayTek Vigor AP910C version 1.2.0 RC3 build r6594, consider disabling the
goform/setSnmp endpoint until a patch is available to prevent exploitation. Restrict access to the SNMP configuration to minimize the risk of unauthorized changes.Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Draytek Vigor Ap910C