CSRF Vulnerability in NETGEAR WNR3500U and WNR3500L Routers
CVE-2013-3516
6.5MEDIUM
Summary
The NETGEAR WNR3500U and WNR3500L routers are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability due to an insecure method of generating form tokens based solely on the current date and time. This design flaw allows attackers to easily predict and guess the CSRF tokens, creating an opportunity for unauthorized commands to be executed on behalf of users. Attackers exploiting this vulnerability can potentially manipulate router settings or carry out harmful actions without the user's consent, compromising the security of the network and connected devices.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved