PT-2026-25784 · Shenzhen Hereta Technology Co. · Hereta Eth-Imc408M

Kazuma Matsumoto

·

Published

2026-03-16

·

Updated

2026-03-17

·

CVE-2026-29521

CVSS v3.1
4.3
VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a cross-site request forgery vulnerability that allows attackers to modify device configuration by exploiting missing CSRF protections in setup.cgi. Attackers can host malicious pages that submit forged requests using automatically-included HTTP Basic Authentication credentials to add RADIUS accounts, alter network settings, or trigger diagnostics.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-29521

Affected Products

Hereta Eth-Imc408M