CVE-2016-8718
high
CVSS v3
8.8
CVSS v2
6.8
VIR risk
8.8
Description
An exploitable Cross-Site Request Forgery vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted form can trick a client into making an unintentional request to the web server which will be treated as an authentic request.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: talos-cna@cisco.com — http://www.talosintelligence.com/reports/TALOS-2016-0232/
References
CWEs
CWE-352
Verify integrity in audit chain (admin only). AS-IS.