VYPR
Unrated severityNVD Advisory· Published Nov 21, 2022· Updated Apr 29, 2025

CVE-2020-23582

CVE-2020-23582

Description

A vulnerability in the "/admin/wlmultipleap.asp" of optilink OP-XT71000N version: V2.2 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to create Multiple WLAN BSSID.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-site request forgery in /admin/wlmultipleap.asp of optilink OP-XT71000N allows unauthenticated remote attackers to create multiple WLAN BSSIDs.

Vulnerability

The /admin/wlmultipleap.asp endpoint in optilink OP-XT71000N firmware version OP_V3.3.1-191028 (hardware version V2.2) is vulnerable to cross-site request forgery (CSRF). An unauthenticated attacker can trick an authenticated administrator into performing unintended actions, such as creating multiple WLAN BSSIDs, without their consent [1].

Exploitation

An attacker needs to craft a malicious web page or link that, when visited by an authenticated administrator, triggers a forged HTTP request to /admin/wlmultipleap.asp. The request is automatically sent with the administrator's cookies, allowing the attacker to create arbitrary WLAN BSSIDs on the device [1].

Impact

Successful exploitation allows the attacker to create multiple WLAN BSSIDs on the device, potentially leading to network configuration changes, denial of service, or unauthorized network access. The attacker does not need authentication credentials to execute the CSRF attack, but the victim must have an active session [1].

Mitigation

As of the latest available information, no official patch has been released by optilink. Users are advised to implement general CSRF protections, such as using anti-CSRF tokens or ensuring the administration interface is only accessible over trusted networks. The device may be end-of-life; consider replacing it with a supported alternative [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

News mentions

0

No linked articles in our index yet.