Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Atsuo Sakurai

Researcher fromTECHMATRIX CORPORATION
#19864of 53,635
13.1Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2021-14102
4.3
2021-02-12
Logitech · Logitec Lan-W300N/Rs · CVE-2021-20641
Name of the Vulnerable Software and Affected Versions: LOGITEC LAN-W300N/RS (affected versions not specified) Description: A cross-site request forgery (CSRF) issue allows remote attackers to hijack the authentication of administrators via a specially crafted URL, potentially leading to unintended operations on the device, such as changes to device settings. Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2017-8552
8.8
2017-05-22
Lg · L-04D · CVE-2016-4854
**Name of the Vulnerable Software and Affected Versions** L-04D firmware versions V10a through V10b **Description** A cross-site request forgery (CSRF) issue allows remote attackers to hijack the authentication of administrators, enabling them to perform arbitrary operations. The exact vectors used for exploitation are not specified. **Recommendations** For L-04D firmware versions V10a and V10b, consider implementing additional authentication checks to prevent CSRF attacks, such as token-based validation, until a patched version is available.