PT-2024-13467 · Realtek · Realtek Rtl819X Jungle Sdk

Francesco Benvenuto

·

Published

2024-07-08

·

Updated

2024-07-11

·

CVE-2023-47677

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Realtek rtl819x Jungle SDK version 3.4.11
Description A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality. A specially crafted network request can lead to CSRF, allowing an attacker to send an HTTP request to trigger this issue.
Recommendations For Realtek rtl819x Jungle SDK version 3.4.11, consider disabling the boa CSRF protection functionality as a temporary workaround until a patch is available. Restrict access to the vulnerable SDK to minimize the risk of exploitation. Avoid using the vulnerable functionality in the affected SDK until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-47677

Affected Products

Realtek Rtl819X Jungle Sdk