CVE-2007-4822: CSRF
Cross-site request forgery (CSRF) vulnerability in the device management interface in Buffalo AirStation WHR-G54S 1.20 allows remote attackers to make configuration changes as an administrator via HTTP requests to certain HTML pages in the res parameter with an inp req parameter to cgi-bin/cgi, as demonstrated by accessing (1) ap.html and (2) filterip.html.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4822?
CVE-2007-4822 is classified as a medium severity vulnerability due to its potential for unauthorized configuration changes.
How do I fix CVE-2007-4822?
To remediate CVE-2007-4822, it is recommended to update the firmware of Buffalo AirStation WHR-G54S to the latest version.
What type of attack does CVE-2007-4822 exploit?
CVE-2007-4822 exploits a cross-site request forgery (CSRF) vulnerability.
Which devices are affected by CVE-2007-4822?
CVE-2007-4822 specifically affects the Buffalo AirStation WHR-G54S with firmware version 1.20.
Can CVE-2007-4822 be exploited remotely?
Yes, CVE-2007-4822 can be exploited remotely by sending crafted HTTP requests to the vulnerable device.