HIGH · 8.8

CVE-2023-41086

Cross-site request forgery (CSRF) vulnerability exists in FURUNO SYSTEMS wireless LAN access point devices. If a user views a malicious page while logged in, unintended operations may be performed. Af...

Vulnerability Description

Cross-site request forgery (CSRF) vulnerability exists in FURUNO SYSTEMS wireless LAN access point devices. If a user views a malicious page while logged in, unintended operations may be performed. Affected products and versions are as follows: ACERA 1210 firmware ver.02.36 and earlier, ACERA 1150i firmware ver.01.35 and earlier, ACERA 1150w firmware ver.01.35 and earlier, ACERA 1110 firmware ver.01.76 and earlier, ACERA 1020 firmware ver.01.86 and earlier, ACERA 1010 firmware ver.01.86 and earlier, ACERA 950 firmware ver.01.60 and earlier, ACERA 850F firmware ver.01.60 and earlier, ACERA 900 firmware ver.02.54 and earlier, ACERA 850M firmware ver.02.06 and earlier, ACERA 810 firmware ver.03.74 and earlier, and ACERA 800ST firmware ver.07.35 and earlier. They are affected when running in ST(Standalone) mode.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
FurunosystemsAcera 1210 Firmware<= 02.36
FurunosystemsAcera 1210-
FurunosystemsAcera 1150I Firmware<= 01.35
FurunosystemsAcera 1150I-
FurunosystemsAcera 1150W Firmware<= 01.35
FurunosystemsAcera 1150W-
FurunosystemsAcera 1110 Firmware<= 01.76
FurunosystemsAcera 1110-
FurunosystemsAcera 1020 Firmware<= 01.86
FurunosystemsAcera 1020-
FurunosystemsAcera 1010 Firmware<= 01.86
FurunosystemsAcera 1010-
FurunosystemsAcera 950 Firmware<= 01.60
FurunosystemsAcera 950-
FurunosystemsAcera 850F Firmware<= 01.60
FurunosystemsAcera 850F-
FurunosystemsAcera 900 Firmware<= 02.54
FurunosystemsAcera 900-
FurunosystemsAcera 850M Firmware<= 02.06
FurunosystemsAcera 850M-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-41086?

CVE-2023-41086 is a vulnerability with a CVSS score of 8.8 (HIGH). Cross-site request forgery (CSRF) vulnerability exists in FURUNO SYSTEMS wireless LAN access point devices. If a user views a malicious page while logged in, unintended operations may be performed. Af...

How severe is CVE-2023-41086?

CVE-2023-41086 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-41086?

Check the references section above for vendor advisories and patch information. Affected products include: Furunosystems Acera 1210 Firmware, Furunosystems Acera 1210, Furunosystems Acera 1150I Firmware, Furunosystems Acera 1150I, Furunosystems Acera 1150W Firmware.