Tenda AC18 Vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2024-2559
Key Information:
Badges
Summary
A vulnerability has been identified in the Tenda AC18 router, specifically affecting the fromSysToolReboot function located in the /goform/SysToolReboot file. This vulnerability allows for cross-site request forgery (CSRF), enabling an attacker to execute unauthorized actions on behalf of a user without their consent. Exploiting this vulnerability can lead to unauthorized remote access and manipulation of the device settings. The risk is compounded by the public disclosure of the exploit, making it crucial for users to assess their systems and implement proper security measures. The vendor, Tenda, has not responded to inquiries regarding this vulnerability, emphasizing the urgency for users to take immediate action to protect their networks.
Affected Version(s)
AC18 15.03.05.05
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved