CVE-2016-10863: CSRF
Published Aug 8, 2019
·Updated
Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure.
Affected Software
4 affected components
Edimax EW-7438RPn Mini firmware
Edimax EW-7438RPn Mini
Edimax 7237rpd Firmware
Edimax 7237rpd
Event History
Aug 8, 2019
CVE Published
via MITRE·08:02 PM
Data Sourced
via MITRE·08:02 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10863?
CVE-2016-10863 is classified as a medium severity vulnerability due to the potential for unauthorized access to sensitive information.
2
How do I fix CVE-2016-10863?
To fix CVE-2016-10863, update the firmware of your Edimax Wi-Fi Extender devices to the latest version provided by the manufacturer.
3
What type of attack does CVE-2016-10863 involve?
CVE-2016-10863 involves a Cross-Site Request Forgery (CSRF) attack that can lead to the disclosure of the Pre-Shared Key (PSK).
4
Which devices are affected by CVE-2016-10863?
CVE-2016-10863 affects Edimax EW-7438RPN Mini and Edimax 7237RPD devices running vulnerable firmware versions.
5
Can CVE-2016-10863 lead to further exploitation?
Yes, if exploited, CVE-2016-10863 can allow attackers to obtain the Wi-Fi PSK, potentially leading to unauthorized access to the network.