PT-2025-23437 · Unknown · Mist Community Edition

Alex Perrakis

+3

·

Published

2025-06-01

·

Updated

2025-11-25

·

CVE-2025-5410

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mist Community Edition versions up to 4.7.1
Description A vulnerability was found in the function session start response of the file src/mist/api/auth/middleware.py. This issue leads to cross-site request forgery and can be initiated remotely.
Recommendations For Mist Community Edition versions up to 4.7.1, upgrade to version 4.7.2 to address this issue.

Exploit

Fix

Missing Authorization

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-5410

Affected Products

Mist Community Edition