"Interest in computer security is driven by events, and the number of events is increasing dramatically. - Ralph Merkle"

RSS

HIO-2009-0405 Linksys WRT160N CSRF PDF Print E-mail

The Linksys WRT160N Wireless-N Broadband Router exhibits a vulnerability which can be exploited by malicious people to conduct cross-site request forgery attacks.

The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the request. This can be exploited to e.g. perform all administrative actions by enticing a logged-in administrator to visit a malicious site.

The vulnerability is reported in hardware version 1 and firmware version 1.02.2. Other versions may also be affected.

References:

CVE-2009-pending

BID: 34448

VUPEN: 2009-0982

Nessus:N/A

OSVDB: 53414

SA: 34625  

XF: 49775

Related: 

Vendor Solution:


 
< Prev   Next >