CVE-2024-26153

HIGH

ETIC Telecom Remote Access Server Firmware < 4.9.19 - Cross-Site Request Forgery via setconf Method

Title source: llm
STIX 2.1

Description

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (CSRF). An external attacker with no access to the device can force the end user into submitting a "setconf" method request, not requiring any CSRF token, which can lead into denial of service on the device.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-22-307-01

Scores

CVSS v3 7.4
EPSS 0.0017
EPSS Percentile 6.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
etictelecom/remote_access_server_firmware < 4.9.19
Published Jan 17, 2025
Tracked Since Feb 18, 2026