PoC Index

CVE-2013-3312

HIGH 8.8EPSS 0.9%

Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to hijack the authentication of unspecified victims for requests that change (1) passwords or (2) firewall configuration, as demonstrated by a request to set_users.cgi.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
0.89% chance of exploitation in the next 30 days, 57th percentile
Published
2019-11-21
Updated
2024-08-06

Proof-of-concept exploits (1)

References

Related