PT-2026-26039 · Unknown · Link Aggregation
Gabriele Quagliarella
·
Published
2026-03-18
·
Updated
2026-03-18
·
CVE-2026-22323
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Versions prior to patchday 2026-05 (affected versions not specified)
Description
A Cross-Site Request Forgery (CSRF) issue exists in the Link Aggregation configuration interface. An unauthenticated remote attacker can deceive authenticated users into submitting unauthorized POST requests to the device. This manipulation can silently modify the device’s configuration without the user’s awareness or permission. The impact on availability is considered low, as the device automatically recovers after a successful attack without requiring external intervention.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Link Aggregation