CVE-2021-47722

LOW

Zucchetti Axess CLOKI Access Control 1.64 - CSRF

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-47722. PoCs published by LiquidWorm.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in Zucchetti Axess CLOKI Access Control 1.64, allowing an attacker to disable or enable access control settings via a malicious HTML form. The vulnerability arises due to the lack of validity checks for HTTP requests.

Description

Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to manipulate access control settings without user interaction. Attackers can craft malicious web pages with hidden forms to disable or modify access control parameters by tricking authenticated users into loading the page.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappshardware
https://www.exploit-db.com/exploits/50595

This exploit demonstrates a CSRF vulnerability in Zucchetti Axess CLOKI Access Control 1.64, allowing an attacker to disable or enable access control settings via a malicious HTML form. The vulnerability arises due to the lack of validity checks for HTTP requests.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Zucchetti Axess CLOKI Access Control 1.64
Auth required
Prerequisites: Victim must be authenticated in the target application · Victim must visit a malicious webpage
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/50595
Various Sources product
https://www.axesstmc.com
Third Party Advisory third-party-advisory
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5689.php

Scores

CVSS v3 3.5
EPSS 0.0018
EPSS Percentile 7.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
Axesstmc/Zucchetti Axess CLOKI Access Control 1.64
Published Dec 23, 2025
Tracked Since Feb 18, 2026