CSRF Vulnerability in NETGEAR WNR3500U and WNR3500L Routers
CVE-2013-3516

6.5MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
13 November 2019

Summary

The NETGEAR WNR3500U and WNR3500L routers are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability due to an insecure method of generating form tokens based solely on the current date and time. This design flaw allows attackers to easily predict and guess the CSRF tokens, creating an opportunity for unauthorized commands to be executed on behalf of users. Attackers exploiting this vulnerability can potentially manipulate router settings or carry out harmful actions without the user's consent, compromising the security of the network and connected devices.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.