Description
A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not implement CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft a malicious webpage that sends forged HTTP requests to configuration endpoints. If an authenticated administrator visits the malicious webpage, the victim-s browser automatically includes the valid session cookie in the request, allowing the router to process the request as a legitimate administrative action.
CVSS 8.8EPSS 0.173%Risque 0.89
Voir la source- Publication
- 2026-04-30 16:16:43
- Versions concernées
- <1.0.1,==1.0.0
- Type
- Micrologiciel
- Vecteur
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H