CVE-2025-27579
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
03/03/2025
Last modified:
04/03/2025
Description
In Bitaxe ESP-Miner before 2.5.0 with AxeOS, one can use an /api/system CSRF attack to update the payout address (aka stratumUser) for a Bitaxe Bitcoin miner, or change the frequency and voltage settings.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM