CVE-2024-45372

MEDIUM

MZK-DP300N Firmware <= 1.04 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious page while logging in to the web management page of the affected product may lead the user to perform unintended operations such as changing the login password, etc.

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.0017
EPSS Percentile 6.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
planex/mzk-dp300n_firmware < 1.04
Published Sep 26, 2024
Tracked Since Feb 18, 2026