A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the LevelOne WBR-6012 R0.40e6. A specially crafted HTTP request can lead to unauthorized access. An attacker can stage a malicious web page to trigger this vulnerability.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2024-1981 | third party advisory exploit |
https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1981 |