Vulnerability Description
OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, firewall/forwards, firewall/rules, network/wan, network/wan6, or network/lan under /cgi-bin/luci/admin/network/.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openwrt | Openwrt | 18 |
Related Weaknesses (CWE)
References
- https://github.com/openwrt/luci/commit/f8c6eb67cd9da09ee20248fec6ab742069635e47PatchThird Party Advisory
- https://github.com/openwrt/luci/commit/f8c6eb67cd9da09ee20248fec6ab742069635e47PatchThird Party Advisory
FAQ
What is CVE-2019-17367?
CVE-2019-17367 is a vulnerability with a CVSS score of 8.8 (HIGH). OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, firewall/forwards, firewall/rules, network/wan, network/wan6, o...
How severe is CVE-2019-17367?
CVE-2019-17367 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-17367?
Check the references section above for vendor advisories and patch information. Affected products include: Openwrt Openwrt.