CVE-2014-10025

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DAP-1360 with firmware 2.5.4 and earlier allow remote attackers to hijack the authentication of unspecified users for requests that change the (1) Enable Wireless, (2) MBSSID, (3) BSSID, (4) Hide Access Point, (5) SSID, (6) Country, (7) Channel, (8) Wireless mode, or (9) Max Associated Clients setting via a crafted request to index.cgi.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:d-link:dap-1360_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dap-1360:-:*:*:*:*:*:*:*

Information

Published : 2015-01-13 03:59

Updated : 2015-01-13 16:31


NVD link : CVE-2014-10025

Mitre link : CVE-2014-10025


JSON object : View

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

Advertisement

dedicated server usa

Products Affected

d-link

  • dap-1360
  • dap-1360_firmware