Popis
A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not implement CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft a malicious webpage that sends forged HTTP requests to configuration endpoints. If an authenticated administrator visits the malicious webpage, the victim-s browser automatically includes the valid session cookie in the request, allowing the router to process the request as a legitimate administrative action.
CVSS 8.8EPSS 0.173%Riziko 0.89
Zobraziť zdroj- Zverejnené
- 2026-04-30 16:16:43
- Dotknuté verzie
- <1.0.1,==1.0.0
- Typ
- Firmvér
- Vektor
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H