A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://dev.freebox.fr/blog/?p=10222 | vendor advisory |
https://www.gabriel.urdhr.fr/2020/09/23/dns-rebinding-freebox/ | third party advisory exploit |