High severity8.8NVD Advisory· Published Jul 31, 2023· Updated Jun 17, 2026
CVE-2023-33534
CVE-2023-33534
Description
A Cross-Site Request Forgery (CSRF) in Guanzhou Tozed Kangwei Intelligent Technology ZLTS10G software version S10G_3.11.6 allows attackers to takeover user accounts via sending a crafted POST request to /goform/goform_set_cmd_process.
Affected products
3- Guanzhou Tozed Kangwei Intelligent Technology/ZLTS10Gdescription
- Range: = S10G_3.11.6
- cpe:2.3:o:sztozed:zlt_s10g_firmware:3.11.6:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- rodelllemit.medium.com/cve-2023-33534-account-takeover-through-csrf-vulnerability-461de6f1b696nvdExploitTechnical DescriptionThird Party Advisory
News mentions
0No linked articles in our index yet.