CVE-2020-24847 Information
Feb 14, 2021
cve
Description
A Cross-Site Request Forgery (CSRF) vulnerability is identified in FruityWifi through 2.4. Due to a lack of CSRF protection in page_config_adv.php an unauthenticated attacker can lure the victim to visit his website by social engineering or another attack vector. Due to this issue an unauthenticated attacker can change the newSSID and hostapd_wpa_passphrase.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Reference
https://github.com/xtr4nge/FruityWifi/issues/277
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
LOW
Base Score
NONE
Base Severity
4.3
Share on: