### [CVE-2013-3540](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3540) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description Cross-site request forgery (CSRF) vulnerability in cgi-bin/admin/usrgrp.cgi in AirLive POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users. ### POC #### Reference - http://seclists.org/fulldisclosure/2013/Jun/84 - http://seclists.org/fulldisclosure/2013/Jun/84 #### Github No PoCs found on GitHub currently.