Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x57f-4q9r-qvpp

Опубликовано: 18 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 4.3

Описание

Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remote attackers to perform unauthorized administrative actions by inducing logged-in administrators to visit malicious pages. Attackers can exploit the lack of anti-CSRF tokens and request validation to change passwords, upload firmware, reboot the device, perform factory resets, or modify network configurations.

Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remote attackers to perform unauthorized administrative actions by inducing logged-in administrators to visit malicious pages. Attackers can exploit the lack of anti-CSRF tokens and request validation to change passwords, upload firmware, reboot the device, perform factory resets, or modify network configurations.

EPSS

Процентиль: 11%
0.00208
Низкий

5.1 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 4.3
nvd
5 месяцев назад

Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remote attackers to perform unauthorized administrative actions by inducing logged-in administrators to visit malicious pages. Attackers can exploit the lack of anti-CSRF tokens and request validation to change passwords, upload firmware, reboot the device, perform factory resets, or modify network configurations.

CVSS3: 4.3
fstec
5 месяцев назад

Уязвимость микропрограммного обеспечения коммутаторов EDIMAX GS-5008PL, связанная с подделкой межсайтовых запросов, позволяющая нарушителю получить доступ на изменение пароля, перезагрузку устройства и сброс системных настроек

EPSS

Процентиль: 11%
0.00208
Низкий

5.1 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-352