CVE-2024-48846

HIGH

ABB ASPECT/MATRIX/NEXUS Firmware < 3.08.03 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-48846. PoCs published by LiquidWorm.

AI-analyzed exploit summary This HTML file demonstrates a CSRF vulnerability in ABB Cylon Aspect's userManagement.php, allowing unauthorized user addition or deletion via crafted POST requests. The PoC includes forms targeting both PHP and Java endpoints.

Description

Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or changing system settings.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · htmlhardwaremultiple
https://www.exploit-db.com/exploits/52231

This HTML file demonstrates a CSRF vulnerability in ABB Cylon Aspect's userManagement.php, allowing unauthorized user addition or deletion via crafted POST requests. The PoC includes forms targeting both PHP and Java endpoints.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: ABB Cylon Aspect <=3.08.02
No auth needed
Prerequisites: Victim must be authenticated in the target application · Attacker must trick victim into visiting malicious page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 7.1
EPSS 0.0154
EPSS Percentile 81.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (19)
abb/aspect-ent-12_firmware < 3.08.03
abb/aspect-ent-256_firmware < 3.08.03
abb/aspect-ent-2_firmware < 3.08.03
abb/aspect-ent-96_firmware < 3.08.03
abb/matrix-11_firmware < 3.08.03
abb/matrix-216_firmware < 3.08.03
abb/matrix-232_firmware < 3.08.03
abb/matrix-264_firmware < 3.08.03
abb/matrix-296_firmware < 3.08.03
abb/nexus-2128-a_firmware < 3.08.03
... and 9 more
Published Dec 05, 2024
Tracked Since Feb 18, 2026