Description
A cross-site request forgery (CSRF) vulnerability exists in the Linksys Cisco WAG120N wireless router's web administration interface. The device does not implement CSRF tokens or validate the origin of requests.
Impact
An attacker can trick an authenticated administrator into visiting a malicious page that silently modifies router settings, including DNS configuration, wireless security settings, and admin passwords. This allows full control of the network gateway.
Solution
Update the router firmware to the latest version. Use a separate browser for router administration.