Description
Ecessa WANWorx WVR-30 versions before 10.7.4 contain a cross-site request forgery vulnerability that allows attackers to perform administrative actions without request validation. Attackers can craft a malicious web page with a hidden form to create a new superuser account by tricking an authenticated administrator into loading the page.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
10.7.4
10.6.9
10.6.5.2
10.5.4
10.2.24
9.2.24
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/44936 (ExploitDB-44936)
www.ecessa.com (Ecessa Corporation Official Website)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.