Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Edimax GS-5008PL <= 1.00.54 CSRF via Management CGI Endpoints
Vulnerability Description
Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remote attackers to perform unauthorized administrative actions by inducing logged-in administrators to visit malicious pages. Attackers can exploit the lack of anti-CSRF tokens and request validation to change passwords, upload firmware, reboot the device, perform factory resets, or modify network configurations.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
Edimax GS-5008PL 跨站请求伪造漏洞
Vulnerability Description
Edimax GS-5008PL是中国台湾讯舟(Edimax)公司的一款千兆以太网交换机。 Edimax GS-5008PL 1.00.54及之前版本存在跨站请求伪造漏洞,该漏洞源于缺少反CSRF令牌和请求验证,可能导致远程攻击者诱使已登录管理员执行未经授权的管理操作。
CVSS Information
N/A
Vulnerability Type
N/A