Количество 3
Количество 3
CVE-2026-24434
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative functions in the web management interface. The interface does not enforce anti-CSRF tokens or robust origin validation, which can allow an attacker to induce a logged-in administrator to perform unintended state-changing requests and modify router settings.
GHSA-rmf8-4fg8-5v47
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative functions in the web management interface. The interface does not enforce anti-CSRF tokens or robust origin validation, which can allow an attacker to induce a logged-in administrator to perform unintended state-changing requests and modify router settings.
BDU:2026-06996
Уязвимость веб-интерфейса управления микропрограммного обеспечения маршрутизатора Tenda AC7, позволяющая нарушителю осуществить CSRF-атаку
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-24434 Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative functions in the web management interface. The interface does not enforce anti-CSRF tokens or robust origin validation, which can allow an attacker to induce a logged-in administrator to perform unintended state-changing requests and modify router settings. | CVSS3: 6.5 | 0% Низкий | 6 месяцев назад | |
GHSA-rmf8-4fg8-5v47 Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative functions in the web management interface. The interface does not enforce anti-CSRF tokens or robust origin validation, which can allow an attacker to induce a logged-in administrator to perform unintended state-changing requests and modify router settings. | CVSS3: 6.5 | 0% Низкий | 6 месяцев назад | |
BDU:2026-06996 Уязвимость веб-интерфейса управления микропрограммного обеспечения маршрутизатора Tenda AC7, позволяющая нарушителю осуществить CSRF-атаку | CVSS3: 5.3 | 0% Низкий | 6 месяцев назад |
Уязвимостей на страницу