PT-2026-25945 · Edimax · Edimax Gs-5008Pl
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Edimax GS-5008PL firmware versions prior to 1.00.54
Description
The firmware does not properly protect against cross-site request forgery, potentially allowing remote attackers to perform unauthorized administrative actions. An attacker can induce logged-in administrators to visit malicious pages, exploiting the absence of anti-CSRF tokens and request validation. This could allow attackers to change passwords, upload firmware, reboot the device, perform factory resets, or modify network configurations.
Recommendations
Update the firmware to a version newer than 1.00.54.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Edimax Gs-5008Pl