First published: Sun Aug 06 2017(Updated: )
Cross-Site Request Forgery (CSRF) exists on Linksys EA4500 devices with Firmware Version before 2.1.41.164606, as demonstrated by a request to apply.cgi to disable SIP.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Linksys EA4500 Firmware | <=2.0.36 | |
Cisco Linksys EA4500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10677 is considered a medium severity vulnerability due to the risk of Cross-Site Request Forgery.
To mitigate CVE-2017-10677, update the Linksys EA4500 firmware to version 2.1.41.164606 or later.
CVE-2017-10677 affects Linksys EA4500 devices running firmware versions prior to 2.1.41.164606.
CVE-2017-10677 facilitates Cross-Site Request Forgery attacks, allowing unauthorized actions on behalf of authenticated users.
CVE-2017-10677 is a remote vulnerability, allowing attackers to exploit it over the network.