VYPR
Unrated severityNVD Advisory· Published Jun 18, 2019· Updated Aug 5, 2024

CVE-2017-8328

CVE-2017-8328

Description

An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the device does not implement any cross site request forgery protection mechanism which allows an attacker to trick a user who is logged in to the web management interface to change a user's password. Also this is a systemic issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Securifi Almond devices lack CSRF protection, allowing an attacker to trick an authenticated admin into changing the admin password.

Vulnerability

The web management interface on Securifi Almond, Almond+, and Almond 2015 devices running firmware AL-R096 does not implement any cross-site request forgery (CSRF) protection mechanism. This allows an attacker to craft a malicious request that, when triggered by an authenticated administrator, can change the administrative password. The issue is systemic across the affected firmware versions [1][2].

Exploitation

An attacker must first identify a target device and then trick a currently logged-in administrator into visiting a malicious link or webpage. The crafted request (e.g., a GET or POST to the password change endpoint) is executed in the context of the admin's session, altering the password without the admin's knowledge. No additional authentication or network position is required beyond the ability to deliver the malicious payload to the admin [1][2].

Impact

Successful exploitation allows the attacker to change the device's administrative password, granting full control over the web management interface. This can lead to further compromise of the device, including modification of network settings, interception of traffic, or use as a pivot point for attacks on the local network [1][2].

Mitigation

As of the publication date (2019-06-18), no official firmware patch has been released to address this CSRF vulnerability. Users are advised to avoid accessing the web management interface while on untrusted networks, log out immediately after use, and consider using additional network-level protections such as VPNs or firewall rules to restrict access to the device's management interface [1][2].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.