6.8
CVSSv2

CVE-2012-1921

Published: 26/08/2012 Updated: 24/01/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 690
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in goform/admin/formWlEncrypt in Sitecom WLM-2501 allows remote malicious users to hijack the authentication of administrators for requests that change the router passphrase via the pskValue parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

sitecom wlm-2501 -

Exploits

+--------------------------------------------------------------------------------------------------------------------------------+ # Exploit Title : Sitecom WLM-2501 new Multiple CSRF Vulnerabilities # Date : 22-03-2012 # Author : Ivano Binetti (wwwivanobinetticom) # Vendor site : wwwsitecomcom/wirele ...
+--------------------------------------------------------------------------------------------------------------------------------+ # Exploit Title : Sitecom WLM-2501 Change Wireless Passphrase # Date : 13-03-2012 # Author : Ivano Binetti (wwwivanobinetticom) # Vendor site : wwwsitecomcom/wireless-mode ...