CVE-2012-1308: CSRF
Cross-site request forgery (CSRF) vulnerability in redpass.cgi in D-Link DSL-2640B Firmware EU4.00 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1308?
CVE-2012-1308 is a medium severity vulnerability due to its ability to allow unauthorized password changes.
How do I fix CVE-2012-1308?
To fix CVE-2012-1308, update the D-Link DSL-2640B firmware to the latest version that addresses this vulnerability.
What type of attack is CVE-2012-1308 associated with?
CVE-2012-1308 is associated with cross-site request forgery (CSRF) attacks targeting administrator password changes.
Who is affected by CVE-2012-1308?
Users of D-Link DSL-2640B routers running firmware version 4.00 are affected by CVE-2012-1308.
What can attackers achieve with CVE-2012-1308?
Attackers can hijack an administrator's authentication session and change the administrator password without their consent.