CVE-2020-5641

Cross-site request forgery (CSRF) vulnerability in GS108Ev3 firmware version 2.06.10 and earlier allows remote attackers to hijack the authentication of administrators and the product's settings may be changed without the user's intention or consent via unspecified vectors.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:gs108ev3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:gs108ev3:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:34

Type Values Removed Values Added
References () https://jvn.jp/en/jp/JVN27806339/index.html - Third Party Advisory () https://jvn.jp/en/jp/JVN27806339/index.html - Third Party Advisory
References () https://kb.netgear.com/000062496/GS108Ev3-Firmware-Version-2-06-14 - Vendor Advisory () https://kb.netgear.com/000062496/GS108Ev3-Firmware-Version-2-06-14 - Vendor Advisory

Information

Published : 2020-11-24 07:15

Updated : 2024-11-21 05:34


NVD link : CVE-2020-5641

Mitre link : CVE-2020-5641

CVE.ORG link : CVE-2020-5641


JSON object : View

Products Affected

netgear

  • gs108ev3_firmware
  • gs108ev3
CWE
CWE-352

Cross-Site Request Forgery (CSRF)