CVE-2019-17367: CSRF
OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, firewall/forwards, firewall/rules, network/wan, network/wan6, or network/lan under /cgi-bin/luci/admin/network/.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-17367?
CVE-2019-17367 is a vulnerability in OpenWRT firmware version 18.06.4 that allows CSRF attacks via certain URLs.
How severe is CVE-2019-17367?
CVE-2019-17367 has a severity score of 8.8 (high).
What is the affected software of CVE-2019-17367?
The affected software of CVE-2019-17367 is OpenWRT firmware version 18.06.4.
How can the CSRF vulnerability be exploited in CVE-2019-17367?
The CSRF vulnerability in CVE-2019-17367 can be exploited via specific URLs, such as wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, firewall/forwards, firewall/rules, network/wan, network/wan6, or network/lan under /cgi-bin/luci/admin/network/.
Is there a fix available for CVE-2019-17367?
Yes, a fix for CVE-2019-17367 is available in the latest version of OpenWRT firmware.