PT-2026-82790 · Ebyte · Ne2-D11
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ebyte NE2-D11 (affected versions not specified)
Description
The web management interface fails to properly verify the origin or authenticity of submitted requests. This allows an unauthenticated remote attacker to trick an authenticated administrator into visiting a specially crafted page, which can lead to unauthorized configuration changes or a disruption of device availability. This issue is a Cross-Site Request Forgery (CSRF), a type of attack that forces an authenticated user to execute unwanted actions on a web application.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ne2-D11