PT-2026-68146 · Unknown · Openbk7231T
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenBK7231T (affected versions not specified)
Description
The '/cfg wifi set' endpoint in 'src/httpserver/http fns.c' allows configuration changes through a GET request without requiring a Cross-Site Request Forgery (CSRF) token. CSRF is a type of attack that tricks a victim into submitting a malicious request. If the
web admin password enabled parameter is missing from the request, the system clears the web admin password, setting it to an empty string. This allows an attacker to use a one-click payload to hijack the WiFi configuration and disable password protection if an authenticated administrator visits a malicious link.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openbk7231T