CVE-2023-5961

HIGH

Moxa Iologik E1210 Firmware < 3.3 - CSRF

Title source: rule
STIX 2.1

Description

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. An attacker can exploit this vulnerability to trick a client into making an unintentional request to the web server, which will be treated as an authentic request. This vulnerability may lead an attacker to perform operations on behalf of the victimized user.

Exploits (1)

nomisec WORKING POC 1 stars
by HadessCS · poc
https://github.com/HadessCS/CVE-2023-5961

Scores

CVSS v3 8.8
EPSS 0.0014
EPSS Percentile 33.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-352
Status published
Products (10)
moxa/iologik_e1210_firmware < 3.3
moxa/iologik_e1211_firmware < 3.3
moxa/iologik_e1212_firmware < 3.3
moxa/iologik_e1213_firmware < 3.3
moxa/iologik_e1214_firmware < 3.3
moxa/iologik_e1240_firmware < 3.3
moxa/iologik_e1241_firmware < 3.3
moxa/iologik_e1242_firmware < 3.3
moxa/iologik_e1260_firmware < 3.3
moxa/iologik_e1262_firmware < 3.3
Published Dec 23, 2023
Tracked Since Feb 18, 2026