QID 591191
Date Published: 2022-11-18
QID 591191: Moxa AWK-3131A Web Application Cross-Site Request Forgery (CSRF) Vulnerability (TALOS-2016-0232)
Tested Versions
Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client 1.1
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
An exploitable Cross-Site Request Forgery vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted form can trick a client into making an unintentional request to the web server which will be treated as an authentic request.
Solution
Customers are advised to refer to CERT MITIGATIONS section TALOS-2016-0232 for affected packages and patching details.
Vendor References
- TALOS-2016-0232 -
talosintelligence.com/vulnerability_reports/TALOS-2016-0232
CVEs related to QID 591191
Software Advisories
| Advisory ID | Software | Component | Link |
|---|