All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19
are vulnerable to cross-site request forgery (CSRF). An external
attacker with no access to the device can force the end user into
submitting a "setconf" method request, not requiring any CSRF token,
which can lead into denial of service on the device.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 17 Jan 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (CSRF). An external attacker with no access to the device can force the end user into submitting a "setconf" method request, not requiring any CSRF token, which can lead into denial of service on the device. | |
Title | ETIC Telecom Remote Access Server (RAS) Cross-Site Request Forgery | |
Weaknesses | CWE-352 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published: 2025-01-17T16:23:10.357Z
Updated: 2025-01-21T14:45:48.666Z
Reserved: 2024-02-14T22:03:32.379Z
Link: CVE-2024-26153

Updated: 2025-01-21T14:45:45.196Z

Status : Received
Published: 2025-01-17T17:15:10.927
Modified: 2025-01-17T17:15:10.927
Link: CVE-2024-26153

No data.