CVE-2024-26153

Severity CVSS v4.0:
MEDIUM
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
17/01/2025
Last modified:
30/07/2025

Description

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 <br /> are vulnerable to cross-site request forgery (CSRF). An external <br /> attacker with no access to the device can force the end user into <br /> submitting a "setconf" method request, not requiring any CSRF token, <br /> which can lead into denial of service on the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:etictelecom:remote_access_server_firmware:*:*:*:*:*:*:*:* 4.9.19 (excluding)


References to Advisories, Solutions, and Tools