Medium severity4.3NVD Advisory· Published Mar 16, 2026· Updated Apr 10, 2026
CVE-2026-29521
CVE-2026-29521
Description
Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a cross-site request forgery vulnerability that allows attackers to modify device configuration by exploiting missing CSRF protections in setup.cgi. Attackers can host malicious pages that submit forged requests using automatically-included HTTP Basic Authentication credentials to add RADIUS accounts, alter network settings, or trigger diagnostics.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.vulncheck.com/advisories/hereta-eth-imc408m-csrf-via-configuration-setupnvdThird Party Advisory
- web.archive.org/web/20250820105319/http://hereta.com/nvdProduct
News mentions
0No linked articles in our index yet.