Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2020-23586: GitHub - huzaifahussain98/CVE-2020-23586: CSRF allows to Add Network Traffic Control Type Rule

A vulnerability found in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to Add Network Traffic Control Type Rule.

CVE
#csrf#vulnerability#web#git#auth

Name already in use

A tag already exists with the provided branch name. Many Git commands accept both tag and branch names, so creating this branch may cause unexpected behavior. Are you sure you want to create this branch?

1 branch 0 tags

Code

  • Use Git or checkout with SVN using the web URL.

  • Open with GitHub Desktop

  • Download ZIP

Latest commit

Files

Permalink

Failed to load latest commit information.

Type

Name

Latest commit message

Commit time

CVE-2020-23586

OPTILINK E-PON “MODEL NO: OP-XT71000N” with "HARDWARE VERSION: V2.2"; & “FIRMWARE VERSION: OP_V3.3.1-191028”

vulnerability found in the "OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028"which allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to Add Network Traffic Control Type Rule.

TARGET

/net_qos_cls_edit.asp

Attack Vector

net_qos_cls_edit.asp allows to Add Network Traffic Control Type Rule and does not have sufficient CSRF protections.

REGARDS

Huzaifa Hussain

https://twitter.com/disguised_noob

https://www.linkedin.com/in/huzaifa-hussain-046791179

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda