CVE-2019-20071: CSRF
On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Netis DL4323 vulnerability?
The vulnerability ID for this Netis DL4323 vulnerability is CVE-2019-20071.
What is the severity of CVE-2019-20071?
The severity of CVE-2019-20071 is medium with a CVSS score of 6.5.
What is the affected software for CVE-2019-20071?
The affected software for CVE-2019-20071 is Netis DL4343 Firmware.
How does the CSRF vulnerability in CVE-2019-20071 work?
The CSRF vulnerability in CVE-2019-20071 occurs via form2logaction.cgi to delete all logs on Netis DL4323 devices.
Is Netis DL4343 affected by CVE-2019-20071?
No, Netis DL4343 is not affected by CVE-2019-20071.
How can I fix the CSRF vulnerability in CVE-2019-20071?
To fix the CSRF vulnerability in CVE-2019-20071, update Netis DL4323 firmware to the latest version.
Where can I find more information about the vulnerability CVE-2019-20071?
You can find more information about the vulnerability CVE-2019-20071 in the references provided: [1](https://drive.google.com/open?id=1XtSsH-1ApxRS7VExubz8zBEyENVQGhUc), [2](https://drive.google.com/open?id=1p4HJ5C20TqY0rVNffdD5Zd7S_bGvDhnk), [3](https://fatihhcelik.blogspot.com/2019/12/csrf-vulnerability-on-clean-log-netis.html).