PT-2019-7657 · Neet · Neet Airstream Nas
Luke Turvey
·
Published
2019-08-07
·
Updated
2021-06-24
·
CVE-2016-10861
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Neet AirStream NAS version 1.1
Description
The issue allows for CSRF attacks, which can lead to changes in the AP name and password by modifying the settings binary.
Recommendations
For Neet AirStream NAS version 1.1, consider disabling the settings binary modification functionality as a temporary workaround until a patch is available. Restrict access to the settings configuration to minimize the risk of exploitation.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Neet Airstream Nas