A cross-site request forgery web vulnerability has been discovered on Netis WF2419 V2.2.36123 devices. A remote attacker is able to delete Address Reservation List settings.
                
            References
                    | Link | Resource | 
|---|---|
| https://0day.today/exploit/29659 | Exploit Third Party Advisory | 
| https://packetstormsecurity.com/files/146117/netiswf2419-xsrf.txt | Exploit Third Party Advisory VDB Entry | 
| https://www.exploit-db.com/exploits/43919/ | Exploit VDB Entry Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
History
                    No history.
Information
                Published : 2018-01-29 19:29
Updated : 2018-02-14 15:46
NVD link : CVE-2018-6391
Mitre link : CVE-2018-6391
CVE.ORG link : CVE-2018-6391
JSON object : View
Products Affected
                netis-systems
- wf2419
 - wf2419_firmware
 
CWE
                
                    
                        
                        CWE-352
                        
            Cross-Site Request Forgery (CSRF)
