CVE-2020-23589 describes a Cross-Site Request Forgery (CSRF) vulnerability in the OPTILINK OP-XT71000N router, specifically affecting hardware version V2.2 and firmware version OP_V3.3.1-191028. This flaw allows an unauthenticated, remote attacker to force a router reboot, leading to a Denial of Service (DoS). With a CVSS score of 6.5 (Medium), the attack requires user interaction (UI:R) but can be executed with low complexity (AC:L) over the network (AV:N), resulting in high availability impact (A:H). There is currently no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) or significant community discussion has been observed for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.3.1-191028CPE matchmatch criteria | cpe:2.3:o:optilinknetwork:op-xt71000n_firmware:3.3.1-191028:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.