Cross-Site Request Forgery in NETGEAR ReadyNAS Devices
CVE-2018-21160

8HIGH

Key Information:

Vendor
Netgear
Vendor
CVE Published:
23 April 2020

Summary

NETGEAR ReadyNAS devices prior to version 6.9.3 are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability, allowing unauthorized actions to be performed on behalf of authenticated users without their consent. This security oversight can lead to significant risks, making it crucial for users to update their systems to the latest version to mitigate potential breaches.

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.