CVE-2013-2752
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
12/12/2013
Last modified:
11/04/2025
Description
Cross-site request forgery (CSRF) vulnerability in frontview/lib/np_handler.pl in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x before 4.2.24 allows remote attackers to hijack the authentication of users.
Impact
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:netgear:raidiator:*:*:*:*:*:readynas:*:* | 4.1 (including) | 4.1.12 (excluding) |
| cpe:2.3:o:netgear:raidiator:*:*:*:*:*:readynas:*:* | 4.2 (including) | 4.2.24 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.osvdb.org/98825
- http://www.readynas.com/?p=7002
- http://www.tripwire.com/register/security-advisory-netgear-readynas/
- http://www.tripwire.com/state-of-security/vulnerability-management/readynas-flaw-allows-root-access-unauthenticated-http-request/
- http://www.osvdb.org/98825
- http://www.readynas.com/?p=7002
- http://www.tripwire.com/register/security-advisory-netgear-readynas/
- http://www.tripwire.com/state-of-security/vulnerability-management/readynas-flaw-allows-root-access-unauthenticated-http-request/



