PT-2019-6910 · Loftek · Loftek Nexus 543 Ip Camera

Publicado

2019-11-21

·

Atualizado

2019-11-27

·

CVE-2013-3312

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Loftek Nexus 543 IP Camera (affected versions not specified)
Description The issue affects the Loftek Nexus 543 IP Camera, where multiple cross-site request forgery (CSRF) vulnerabilities exist. These vulnerabilities allow remote attackers to hijack the authentication of victims for requests, enabling them to change passwords or firewall configuration. An example of such an exploit is a request to the "set users.cgi" endpoint.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-3312

Produtos afetados

Loftek Nexus 543 Ip Camera