CVE-2026-29521

MEDIUM

Hereta ETH-IMC408M CSRF via Configuration Setup

Title source: cna
STIX 2.1

Description

Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a cross-site request forgery vulnerability that allows attackers to modify device configuration by exploiting missing CSRF protections in setup.cgi. Attackers can host malicious pages that submit forged requests using automatically-included HTTP Basic Authentication credentials to add RADIUS accounts, alter network settings, or trigger diagnostics.

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 7.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (2)
hereta/eth-imc408m_firmware < 1.0.15
Shenzhen Hereta Technology Co., Ltd./Hereta ETH-IMC408M < 1.0.15
Published Mar 16, 2026
Tracked Since Mar 16, 2026