Cross-Site Request Forgery Vulnerability in Tenda Router Firmware
CVE-2022-27374
6.5MEDIUM
Summary
The Tenda AX12 router firmware is susceptible to a Cross-Site Request Forgery (CSRF) attack. This vulnerability can be exploited through specific functions, allowing unauthorized commands to be sent on behalf of an authenticated user without their consent. Attackers can leverage this flaw to manipulate router settings, leading to potential security breaches and unauthorized access. Users are advised to take precautions and update their firmware to protect against potential exploits.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved