Vulnerability Description
A Cross-Site Request Forgery (CSRF) vulnerability is identified in FruityWifi through 2.4. Due to a lack of CSRF protection in page_config_adv.php, an unauthenticated attacker can lure the victim to visit his website by social engineering or another attack vector. Due to this issue, an unauthenticated attacker can change the newSSID and hostapd_wpa_passphrase.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fruitywifi Project | Fruitywifi | <= 2.4 |
Related Weaknesses (CWE)
References
- https://github.com/xtr4nge/FruityWifi/issues/277ExploitIssue TrackingThird Party Advisory
- https://github.com/xtr4nge/FruityWifi/issues/277ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2020-24847?
CVE-2020-24847 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A Cross-Site Request Forgery (CSRF) vulnerability is identified in FruityWifi through 2.4. Due to a lack of CSRF protection in page_config_adv.php, an unauthenticated attacker can lure the victim to v...
How severe is CVE-2020-24847?
CVE-2020-24847 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-24847?
Check the references section above for vendor advisories and patch information. Affected products include: Fruitywifi Project Fruitywifi.