CVE-2008-6823

UnknownEPSS 1.54%

Last modified

CVE-2008-6823 is a vulnerability of currently unknown severity. Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface on the A-LINK WL54AP3 and WL54AP2 access points before firmware 1.4.2-eng1 allow remote attackers to hijack the authentication of administrators for requests that (1) modify the network configuration via certain parameters to goform/formWanTcpipSetup or (2) modify credentials via certain parameters to goform/formPasswordSetup.. EPSS estimates a 1.54% chance of exploitation in the next 30 days.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface on the A-LINK WL54AP3 and WL54AP2 access points before firmware 1.4.2-eng1 allow remote attackers to hijack the authentication of administrators for requests that (1) modify the network configuration via certain parameters to goform/formWanTcpipSetup or (2) modify credentials via certain parameters to goform/formPasswordSetup.

Metrics

EPSS Probability
1.54%

71.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
A-LinkWl54ap2<= 1.4.1
A-LinkWl54ap21.2.0
A-LinkWl54ap21.2.1
A-LinkWl54ap21.2.2
A-LinkWl54ap21.2.3
A-LinkWl54ap21.2.4
A-LinkWl54ap21.2.5
A-LinkWl54ap21.2.6
A-LinkWl54ap21.2.7
A-LinkWl54ap21.2.8
A-LinkWl54ap21.2.9
A-LinkWl54ap21.4.0
A-LinkWl54ap3<= 1.4.1
A-LinkWl54ap31.2.0
A-LinkWl54ap31.2.1
A-LinkWl54ap31.2.2
A-LinkWl54ap31.2.3
A-LinkWl54ap31.2.4
A-LinkWl54ap31.2.5
A-LinkWl54ap31.2.6
A-LinkWl54ap31.2.7
A-LinkWl54ap31.2.8
A-LinkWl54ap31.2.9
A-LinkWl54ap31.4.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2008-6823?
Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface on the A-LINK WL54AP3 and WL54AP2 access points before firmware 1.4.2-eng1 allow remote attackers to hijack the authentication of administrators for requests that (1) modify the network configuration via certain parameters to goform/formWanTcpipSetup or (2) modify credentials via certain parameters to goform/formPasswordSetup.
How severe is CVE-2008-6823?
Severity scoring for CVE-2008-6823 is pending analysis. The EPSS model estimates a 1.54% probability of exploitation in the next 30 days.
How do I fix CVE-2008-6823?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2008-6823?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST