CVE-2008-6823

Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface on the A-LINK WL54AP3 and WL54AP2 access points before firmware 1.4.2-eng1 allow remote attackers to hijack the authentication of administrators for requests that (1) modify the network configuration via certain parameters to goform/formWanTcpipSetup or (2) modify credentials via certain parameters to goform/formPasswordSetup.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
VendorProductVersion
a-linkwl54ap2
𝑥
≤ 1.4.1
a-linkwl54ap2
1.2.0
a-linkwl54ap2
1.2.1
a-linkwl54ap2
1.2.2
a-linkwl54ap2
1.2.3
a-linkwl54ap2
1.2.4
a-linkwl54ap2
1.2.5
a-linkwl54ap2
1.2.6
a-linkwl54ap2
1.2.7
a-linkwl54ap2
1.2.8
a-linkwl54ap2
1.2.9
a-linkwl54ap2
1.4.0
a-linkwl54ap3
𝑥
≤ 1.4.1
a-linkwl54ap3
1.2.0
a-linkwl54ap3
1.2.1
a-linkwl54ap3
1.2.2
a-linkwl54ap3
1.2.3
a-linkwl54ap3
1.2.4
a-linkwl54ap3
1.2.5
a-linkwl54ap3
1.2.6
a-linkwl54ap3
1.2.7
a-linkwl54ap3
1.2.8
a-linkwl54ap3
1.2.9
a-linkwl54ap3
1.4.0
𝑥
= Vulnerable software versions