CVE-2021-40518

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
10/11/2021
Last modified:
15/11/2021

Description

Airangel HSMX Gateway devices through 5.2.04 allow CSRF.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:airangel:hsmx-app-25_firmware:*:*:*:*:*:*:*:* 5.2.04 (including)
cpe:2.3:h:airangel:hsmx-app-25:-:*:*:*:*:*:*:*
cpe:2.3:o:airangel:hsmx-app-100_firmware:*:*:*:*:*:*:*:* 5.2.04 (including)
cpe:2.3:h:airangel:hsmx-app-100:-:*:*:*:*:*:*:*
cpe:2.3:o:airangel:hsmx-app-1000_firmware:*:*:*:*:*:*:*:* 5.2.04 (including)
cpe:2.3:h:airangel:hsmx-app-1000:-:*:*:*:*:*:*:*
cpe:2.3:o:airangel:hsmx-app-5000_firmware:*:*:*:*:*:*:*:* 5.2.04 (including)
cpe:2.3:h:airangel:hsmx-app-5000:-:*:*:*:*:*:*:*
cpe:2.3:o:airangel:hsmx-app-20000_firmware:*:*:*:*:*:*:*:* 5.2.04 (including)
cpe:2.3:h:airangel:hsmx-app-20000:-:*:*:*:*:*:*:*