CVE-2025-67013
PoC —CVSS 3.1
6.5 medium
EPSS
<1%p7
Published
()
Modified
Description
The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin/Referer validation) on critical configuration endpoints.
- Vendors
- etlsystems
- Products
- d0116s1ula-22454 firmware, d0116s1uia-22474 firmware, c0401s1ula-22418 firmware, c0801s1ula-22420 firmware, c1601s1ula-22422 firmware, c0401s1ula-22455 firmware, c0801s1ula-22457 firmware, c1601s1ula-22459 firmware, c1601s1uia-22479 firmware, d0104d1ula-22411 firmware, d0108d1ula-22413 firmware, d0104d1ula-22451 firmware
- Weakness
- CWE-352
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.