CVE-2018-12456
Summary
| CVE | CVE-2018-12456 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-10 21:29:00 UTC |
| Updated | 2018-11-28 18:08:00 UTC |
| Description | Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attackers to perform actions such as changing the wireless SSID, rebooting the device, editing access control lists, or activating remote access. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Intelbras | Nplug | - | All | All | All |
| Hardware | Intelbras | Nplug | - | All | All | All |
| Operating System | Intelbras | Nplug Firmware | 1.0.0.14 | All | All | All |
| Operating System | Intelbras | Nplug Firmware | 1.0.0.14 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: Multiple vulnerabilities in NPLUG wireless repeater | FULLDISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.