CVE-2023-41086
Last modified
CVE-2023-41086 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Cross-site request forgery (CSRF) vulnerability exists in FURUNO SYSTEMS wireless LAN access point devices. If a user views a malicious page while logged in, unintended operations may be performed. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Cross-site request forgery (CSRF) vulnerability exists in FURUNO SYSTEMS wireless LAN access point devices. If a user views a malicious page while logged in, unintended operations may be performed. Affected products and versions are as follows: ACERA 1210 firmware ver.02.36 and earlier, ACERA 1150i firmware ver.01.35 and earlier, ACERA 1150w firmware ver.01.35 and earlier, ACERA 1110 firmware ver.01.76 and earlier, ACERA 1020 firmware ver.01.86 and earlier, ACERA 1010 firmware ver.01.86 and earlier, ACERA 950 firmware ver.01.60 and earlier, ACERA 850F firmware ver.01.60 and earlier, ACERA 900 firmware ver.02.54 and earlier, ACERA 850M firmware ver.02.06 and earlier, ACERA 810 firmware ver.03.74 and earlier, and ACERA 800ST firmware ver.07.35 and earlier. They are affected when running in ST(Standalone) mode.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Furunosystems | Acera 1210 Firmware | <= 02.36 |
| Furunosystems | Acera 1150i Firmware | <= 01.35 |
| Furunosystems | Acera 1150w Firmware | <= 01.35 |
| Furunosystems | Acera 1110 Firmware | <= 01.76 |
| Furunosystems | Acera 1020 Firmware | <= 01.86 |
| Furunosystems | Acera 1010 Firmware | <= 01.86 |
| Furunosystems | Acera 950 Firmware | <= 01.60 |
| Furunosystems | Acera 850f Firmware | <= 01.60 |
| Furunosystems | Acera 900 Firmware | <= 02.54 |
| Furunosystems | Acera 850m Firmware | <= 02.06 |
| Furunosystems | Acera 810 Firmware | <= 03.74 |
| Furunosystems | Acera 800st Firmware | <= 07.35 |
References
- https://jvn.jp/en/vu/JVNVU94497038/Third Party Advisory
- https://jvn.jp/en/vu/JVNVU94497038/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-41086?
How severe is CVE-2023-41086?
How do I fix CVE-2023-41086?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-4108Mattermost fails to sanitize post metadata during audit logg…7.5
- CVE-2023-41080URL Redirection to Untrusted Site ('Open Redirect') vulnerab…6.1
- CVE-2023-41081Important: Authentication Bypass CVE-2023-41081 The mod_jk …7.5
- CVE-2023-41082Null pointer dereference for some Intel(R) CST software befo…4.4
- CVE-2023-41084 Session management within the web application is …9.8
- CVE-2023-41085 When IPSec is configured on a Virtual Server, undisclosed t…7.5
- CVE-2023-41088 The affected product is vulnerable to a cleartext…6.5
- CVE-2023-41089 The affected product is vulnerable to an improper a…8.8
- CVE-2023-4109The Ninja Forms WordPress Ninja Forms Contact Form WordPress…4.8
- CVE-2023-41090Race condition in some Intel(R) MAS software before version …6.4
- CVE-2023-41091Uncontrolled search path for some Intel(R) MPI Library Softw…7.8
- CVE-2023-41092Unchecked return value in SDM firmware for Intel(R) Stratix …7.6
Are you affected by CVE-2023-41086?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
