PT-2026-25784 · Shenzhen Hereta Technology Co. · Hereta Eth-Imc408M
Kazuma Matsumoto
·
Published
2026-03-16
·
Updated
2026-03-17
·
CVE-2026-29521
CVSS v3.1
4.3
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a cross-site request forgery vulnerability that allows attackers to modify device configuration by exploiting missing CSRF protections in setup.cgi. Attackers can host malicious pages that submit forged requests using automatically-included HTTP Basic Authentication credentials to add RADIUS accounts, alter network settings, or trigger diagnostics.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hereta Eth-Imc408M