CVE-2019-19516: CSRF
Published Dec 2, 2019
·Updated
Intelbras WRN 150 1.0.18 devices allow CSRF via GO=systempassword.asp to the goform/SysToolChangePwd URI to change a password.
Affected Software
2 affected components
Intelbras Wrn 150 Firmware=1.0.18
Intelbras WRN 150
Event History
Dec 2, 2019
CVE Published
via MITRE·10:10 PM
Data Sourced
via MITRE·10:10 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Intelbras WRN 150 device vulnerability?
The vulnerability ID is CVE-2019-19516.
2
What is the severity level of CVE-2019-19516?
The severity level of CVE-2019-19516 is medium with a CVSS score of 6.5.
3
How can an attacker exploit CVE-2019-19516?
An attacker can exploit CVE-2019-19516 by performing a Cross-Site Request Forgery attack via the goform/SysToolChangePwd URI.
4
What is the affected software version of Intelbras WRN 150 devices?
The affected software version is 1.0.18.
5
Are there any references available for CVE-2019-19516?
Yes, you can find more information about CVE-2019-19516 at the following references: [Packet Storm Security](http://packetstormsecurity.com/files/155557/Intelbras-Router-RF1200-1.1.3-Cross-Site-Request-Forgery.html) and [Exploit-DB](https://www.exploit-db.com/exploits/47545).