ToMAX R60G R60GV2-V2.0-v.2.6.3-170330 devices do not have any protection against a CSRF attack.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://iscouncil.blogspot.com/2017/08/cross-site-request-forgery_11.html | technical description exploit |
http://www.securityfocus.com/bid/100438 | vdb entry third party advisory |