VYPR
Unrated severityNVD Advisory· Published Jan 17, 2025· Updated Jan 21, 2025

ETIC Telecom Remote Access Server (RAS) Cross-Site Request Forgery

CVE-2024-26153

Description

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (CSRF). An external attacker with no access to the device can force the end user into submitting a "setconf" method request, not requiring any CSRF token, which can lead into denial of service on the device.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.