Medium severity4.3NVD Advisory· Published Oct 23, 2020· Updated Jun 17, 2026
CVE-2020-24847
CVE-2020-24847
Description
A Cross-Site Request Forgery (CSRF) vulnerability is identified in FruityWifi through 2.4. Due to a lack of CSRF protection in page_config_adv.php, an unauthenticated attacker can lure the victim to visit his website by social engineering or another attack vector. Due to this issue, an unauthenticated attacker can change the newSSID and hostapd_wpa_passphrase.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- FruityWifi/FruityWifidescription
- Range: <=2.4
Patches
Vulnerability mechanics
References
1- github.com/xtr4nge/FruityWifi/issues/277nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.