Tenda AC18 Vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2024-2559
What is CVE-2024-2559?
A vulnerability has been identified in the Tenda AC18 router, specifically affecting the fromSysToolReboot function located in the /goform/SysToolReboot file. This vulnerability allows for cross-site request forgery (CSRF), enabling an attacker to execute unauthorized actions on behalf of a user without their consent. Exploiting this vulnerability can lead to unauthorized remote access and manipulation of the device settings. The risk is compounded by the public disclosure of the exploit, making it crucial for users to assess their systems and implement proper security measures. The vendor, Tenda, has not responded to inquiries regarding this vulnerability, emphasizing the urgency for users to take immediate action to protect their networks.
Affected Version(s)
AC18 15.03.05.05
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved