CVE-2018-12456

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
10/10/2018
Last modified:
28/11/2018

Description

Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attackers to perform actions such as changing the wireless SSID, rebooting the device, editing access control lists, or activating remote access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:intelbras:nplug_firmware:1.0.0.14:*:*:*:*:*:*:*
cpe:2.3:h:intelbras:nplug:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools