Cross-Site Request Forgery in Intelbras WRN 150 Router
CVE-2019-19516

6.5MEDIUM

Key Information:

Vendor

Intelbras

Vendor
CVE Published:
2 December 2019

What is CVE-2019-19516?

The Intelbras WRN 150 router version 1.0.18 is susceptible to a Cross-Site Request Forgery vulnerability. This flaw allows an attacker to exploit the goform/SysToolChangePwd endpoint, potentially permitting them to change a user's password without their consent. Successful exploitation of this vulnerability may lead to unauthorized access and control over the device, making it essential for users to implement protective measures.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.