CVE-2018-6391: CSRF
Published Jan 29, 2018
·Updated
A cross-site request forgery web vulnerability has been discovered on Netis WF2419 V2.2.36123 devices. A remote attacker is able to delete Address Reservation List settings.
Affected Software
4 affected components
netis-systems Wf2419 Firmware=2.2.36123
netis-systems Wf2419
All of the following
netis-systems Wf2419 Firmware=2.2.36123
netis-systems Wf2419
Event History
Jan 29, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this cross-site request forgery web vulnerability?
The vulnerability ID for this cross-site request forgery web vulnerability is CVE-2018-6391.
2
What is the severity rating of CVE-2018-6391?
CVE-2018-6391 has a severity rating of 8.8 (high).
3
What is the description of CVE-2018-6391?
CVE-2018-6391 is a cross-site request forgery web vulnerability discovered on Netis WF2419 V2.2.36123 devices, allowing a remote attacker to delete Address Reservation List settings.
4
Is the Netis-systems Wf2419 affected by CVE-2018-6391?
No, Netis-systems Wf2419 is not affected by CVE-2018-6391.
5
How can I fix the vulnerability CVE-2018-6391?
To fix CVE-2018-6391, it is recommended to update the firmware of Netis WF2419 V2.2.36123 devices to a patched version.