CVE-2019-13529: CSRF
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses to maintain communication after a successful login, which would increase the ease of exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13529?
CVE-2019-13529 is considered to have a medium severity rating due to its potential for remote exploitation.
How do I fix CVE-2019-13529?
To fix CVE-2019-13529, upgrade the Sunny WebBox firmware to version 1.7 or higher.
What type of attack does CVE-2019-13529 enable?
CVE-2019-13529 enables remote attackers to perform actions with the permissions of the user through a Cross-Site Request Forgery (CSRF) vulnerability.
Who is affected by CVE-2019-13529?
CVE-2019-13529 affects users of the Sunny WebBox Firmware Version 1.6 and prior.
What is the impact of CVE-2019-13529?
The impact of CVE-2019-13529 can lead to unauthorized actions being executed on behalf of authenticated users.