CVE-2020-21884
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
09/04/2021
Last modified:
07/11/2023
Description
Unibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF) vulnerability in /tools/network-trace, /list_users, /list_byod?usertype=raduser, /dhcp_leases, /go?rid=202 in which a specially crafted HTTP request may reconfigure the device.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:indionetworks:unibox_u50_firmware:2.4:*:*:*:*:*:*:* | ||
| cpe:2.3:h:indionetworks:unibox_u50:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:indionetworks:unibox_u500_firmware:2.4:*:*:*:*:*:*:* | ||
| cpe:2.3:h:indionetworks:unibox_u500:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:indionetworks:unibox_u1000_firmware:2.4:*:*:*:*:*:*:* | ||
| cpe:2.3:h:indionetworks:unibox_u1000:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:indionetworks:unibox_u2500_firmware:2.4:*:*:*:*:*:*:* | ||
| cpe:2.3:h:indionetworks:unibox_u2500:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:indionetworks:unibox_u5000_firmware:2.4:*:*:*:*:*:*:* | ||
| cpe:2.3:h:indionetworks:unibox_u5000:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



