CVE-2020-8282

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
14/12/2020
Last modified:
16/12/2020

Description

A security issue was found in EdgePower 24V/54V firmware v1.7.0 and earlier where, due to missing CSRF protections, an attacker would have been able to perform unauthorized remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ui:edgemax_edgepower_24v_firmware:*:*:*:*:*:*:*:* 1.7.0 (including)
cpe:2.3:h:ui:edgemax_edgepower_24v:-:*:*:*:*:*:*:*
cpe:2.3:o:ui:edgemax_edgepower_54v_firmware:*:*:*:*:*:*:*:* 1.7.0 (including)
cpe:2.3:h:ui:edgemax_edgepower_54v:-:*:*:*:*:*:*:*