CVE-2018-5720
Summary
| CVE | CVE-2018-5720 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-29 05:29:00 UTC |
| Updated | 2018-02-21 13:47:00 UTC |
| Description | An issue was discovered on DODOCOOL DC38 3-in-1 N300 Mini Wireless Range Extend RTN2-AW.GD.R3465.1.20161103 devices. A Cross-site request forgery (CSRF) vulnerability allows remote attackers to hijack the authentication of users for requests that modify all the settings. This vulnerability can lead to changing an existing user's username and password, changing the Wi-Fi password, etc. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Dodocool | Dc38 | - | All | All | All |
| Hardware | Dodocool | Dc38 | - | All | All | All |
| Operating System | Dodocool | Dc38 Firmware | rtn2-aw.gd.r3465.1.20161103 | All | All | All |
| Operating System | Dodocool | Dc38 Firmware | rtn2-aw.gd.r3465.1.20161103 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Dodocool DC38 N300 - Cross-site Request Forgery - Hardware webapps Exploit | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.