PT-2020-15841 · Fruitywifi · Fruitywifi
Published
2020-10-23
·
Updated
2020-10-27
·
CVE-2020-24847
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FruityWifi versions through 2.4
Description
A Cross-Site Request Forgery issue is identified due to a lack of protection in the page config adv.php file. This allows an unauthenticated attacker to change the
newSSID and hostapd wpa passphrase by luring the victim to visit a malicious website through social engineering or another attack vector.Recommendations
For FruityWifi versions through 2.4, consider implementing CSRF protection mechanisms to prevent unauthorized changes to sensitive parameters like
newSSID and hostapd wpa passphrase. As a temporary workaround, restrict access to the page config adv.php file to minimize the risk of exploitation.Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fruitywifi