Описание
Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable ID value, as demonstrated by a /sendrcpackage?keyid=-2544&keysymbol=-4081 request to shut off the device.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:arcelikas:grundig_smart_inter\@ctive_firmware:3.0:*:*:*:*:*:*:*
cpe:2.3:h:arcelikas:grundig_smart_inter\@ctive:-:*:*:*:*:*:*:*
EPSS
Процентиль: 58%
0.00361
Низкий
8.8 High
CVSS3
8.3 High
CVSS2
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 8.8
github
больше 3 лет назад
Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable ID value, as demonstrated by a /sendrcpackage?keyid=-2544&keysymbol=-4081 request to shut off the device.
EPSS
Процентиль: 58%
0.00361
Низкий
8.8 High
CVSS3
8.3 High
CVSS2
Дефекты
CWE-352