PT-2026-26039 · Unknown · Link Aggregation

Gabriele Quagliarella

·

Published

2026-03-18

·

Updated

2026-03-18

·

CVE-2026-22323

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Versions prior to patchday 2026-05 (affected versions not specified)
Description A Cross-Site Request Forgery (CSRF) issue exists in the Link Aggregation configuration interface. An unauthenticated remote attacker can deceive authenticated users into submitting unauthorized POST requests to the device. This manipulation can silently modify the device’s configuration without the user’s awareness or permission. The impact on availability is considered low, as the device automatically recovers after a successful attack without requiring external intervention.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-22323

Affected Products

Link Aggregation