PT-2024-31585 · Planex · Planex Mzk-Dp300N
Kentaro Ishii
·
Published
2024-09-25
·
Updated
2024-10-03
·
CVE-2024-45372
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PLANEX MZK-DP300N firmware versions 1.04 and earlier
Description
The issue is related to a cross-site request forgery vulnerability. Viewing a malicious page while logging in to the web management page of the affected product may lead the user to perform unintended operations, such as changing the login password.
Recommendations
For firmware versions 1.04 and earlier, update to a patched version as soon as possible and enforce strict CSRF token validation.
As a temporary workaround, consider restricting access to the web management page until a patch is available.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Planex Mzk-Dp300N