CVE-2019-17600

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
15/10/2019
Last modified:
16/11/2019

Description

Intelbras IWR 1000N 1.6.4 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:intelbras:iwr_1000n_firmware:1.6.4:*:*:*:*:*:*:*
cpe:2.3:h:intelbras:iwr_1000n:-:*:*:*:*:*:*:*