PT-2025-9235 · Bitaxe · Bitaxe Esp-Miner

Shaunography

·

Published

2025-03-02

·

Updated

2025-03-04

·

CVE-2025-27579

CVSS v3.1

5.4

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Bitaxe ESP-Miner versions prior to 2.5.0
Description The issue allows an attacker to perform a CSRF attack via the "/api/system" API endpoint to update the payout address, also known as stratumUser, for a Bitaxe Bitcoin miner. Additionally, it enables changes to the frequency and voltage settings.
Recommendations For versions prior to 2.5.0, update to version 2.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/api/system" API endpoint to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-27579

Affected Products

Bitaxe Esp-Miner