Cross Site Request Forgery Vulnerability in TP-Link Switches
CVE-2021-31659
8.8HIGH
What is CVE-2021-31659?
TP-Link's TL-SG2005 and TL-SG2008 switches are susceptible to a Cross Site Request Forgery vulnerability. This issue arises from the handling of configuration information within URLs, without implementing any form of token-based authentication. An attacker could exploit this vulnerability by tricking an authorized switch administrator into clicking a malicious link. This action may lead to unauthorized modification of the switch's password and tampering with configuration files, potentially compromising the integrity and security of network operations.