ZeroHour

CVE-2025-67013

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p7
Published
()
Modified
Description

The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin/Referer validation) on critical configuration endpoints.

Vendors
etlsystems
Products
d0116s1ula-22454 firmware, d0116s1uia-22474 firmware, c0401s1ula-22418 firmware, c0801s1ula-22420 firmware, c1601s1ula-22422 firmware, c0401s1ula-22455 firmware, c0801s1ula-22457 firmware, c1601s1ula-22459 firmware, c1601s1uia-22479 firmware, d0104d1ula-22411 firmware, d0108d1ula-22413 firmware, d0104d1ula-22451 firmware
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.