info.cryptobox.com
https://info.cryptobox.com/doc/v4.39/4.39.en CVE-2025-14266
LOW
CSRF in Ercom Cryptobox administration console
Record summary
CVE-2025-14266 has a selected CVSS score of 0.6 (low).
Description
CSRF in Ercom Cryptobox administration console allows attacker to trigger some actions on behalf of a Cryptobox administrator. The attack requires the administrator to browse a malicious web site or to click a link while he has an open session on the administration console.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 17, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
CryptoboxBrowse Ercom / CryptoboxDefault status: unaffected | CVE List | 4.0.0 to < 4.37.229 | affected |
| 4.38.0 to < 4.39.200 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-14266