VYPR
Unrated severityNVD Advisory· Published Nov 23, 2022· Updated Apr 29, 2025

CVE-2020-23593

CVE-2020-23593

Description

A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2, Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross site request forgery (CSRF) attack to enable syslog mode through ' /mgm_log_cfg.asp.' The system starts to log events, 'Remote' mode or 'Both' mode on "Syslog -- Configuration page" logs events and sends to remote syslog server IP and Port.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF in OPTILINK OP-XT71000N allows unauthenticated remote attacker to enable syslog mode and send logs to attacker-controlled server.

Vulnerability

The OPTILINK OP-XT71000N router with Hardware Version V2.2 and Firmware Version OP_V3.3.1-191028 contains a cross-site request forgery (CSRF) vulnerability in the /mgm_log_cfg.asp endpoint. An unauthenticated remote attacker can exploit this to enable syslog mode without the administrator's consent [1].

Exploitation

The attacker crafts a malicious web page or link that, when visited by an authenticated administrator, triggers a CSRF request to /mgm_log_cfg.asp. This request changes the syslog configuration to 'Remote' or 'Both' mode, causing the device to send log events to a remote syslog server specified by the attacker (IP and port). No authentication is required for the CSRF attack itself, but the administrator must be logged into the router's web interface [1].

Impact

Successful exploitation allows the attacker to receive sensitive system logs from the router, potentially including information about network activity, authentication attempts, and other events. This constitutes an information disclosure vulnerability [1].

Mitigation

As of the publication date (2022-11-23), no official patch or firmware update has been released by OPTILINK to address this CSRF vulnerability. Users should consider restricting access to the router's management interface, using strong passwords, and monitoring for suspicious activity. Alternatively, disabling the web interface or using a VPN may reduce exposure [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

News mentions

0

No linked articles in our index yet.