PT-2024-37152 · Comtrend · Comtrend Router Grg-4280Us+1

Gabriel Gonzalez García

·

Published

2024-06-10

·

Updated

2024-06-10

·

CVE-2024-5786

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Comtrend router WLD71-T1 version 2.0.201820 Comtrend router GRG-4280us version
Description: The issue allows an attacker to force an end user to execute unwanted actions in a web application to which he is authenticated. This is a Cross-Site Request Forgery vulnerability.
Recommendations: For Comtrend router WLD71-T1 version 2.0.201820, update to a version that includes a fix for this issue. For Comtrend router GRG-4280us, update to a version that includes a fix for this issue. As a temporary workaround, consider implementing measures to prevent cross-site request forgery, such as validating requests and using anti-CSRF tokens.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-5786

Affected Products

Comtrend Router Grg-4280Us
Comtrend Router Wld71-T1