CVE-2018-12456: CSRF
Published Oct 10, 2018
·Updated
Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attackers to perform actions such as changing the wireless SSID, rebooting the device, editing access control lists, or activating remote access.
Affected Software
2 affected components
Intelbras Nplug Firmware=1.0.0.14
Intelbras NPLUG
Event History
Oct 10, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2018-12456.
2
What is the severity of CVE-2018-12456?
The severity of CVE-2018-12456 is high with a CVSS score of 8.8.
3
Which devices are affected by CVE-2018-12456?
The Intelbras NPLUG 1.0.0.14 wireless repeater devices are affected by CVE-2018-12456.
4
What actions can attackers perform with CVE-2018-12456?
Attackers can perform actions such as changing the wireless SSID, rebooting the device, editing access control lists, or activating remote access with CVE-2018-12456.
5
Is there a fix available for CVE-2018-12456?
Currently, there is no available fix for CVE-2018-12456. It is recommended to contact the vendor for further information.