PT-2020-13620 · Fastweb · Fastgate Gpon Fga2130Fwb

Luca Di Domenico

·

Published

2020-11-24

·

Updated

2020-12-03

·

CVE-2020-13620

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26
Description The issue allows for Cross-Site Request Forgery (CSRF) attacks via the router administration web panel. This enables an attacker to perform administrative actions, such as modifying the configuration.
Recommendations For Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26, consider updating to a version released after 2020-05-26 to mitigate the risk of CSRF attacks. As a temporary workaround, restrict access to the router administration web panel to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13620

Affected Products

Fastgate Gpon Fga2130Fwb