CVE-2013-5039 EXPLOIT
5.4
MEDIUM · CVSS 2.0 · EPSS 2.1% (pctl 81)
Patch early
A public exploit exists.
Description
Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.11 allows remote attackers to hijack the authentication of administrators for requests that change the WiFi Security field to Deactivated via the WifiSecurity parameter.
Scoring
| CVSS | 5.4 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:A/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 2.13% — more likely to be exploited than 81% of all CVEs |
| Weakness | CWE-352 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-12-30 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| hot | hotbox router |
| hot | hotbox router firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities | 2013-11-08 |
References
→ the Explorer · watch your stack · NVD