Description
Teradek Slice 7.3.15 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft a malicious web page that automatically submits password change requests to the device when a logged-in user visits the page.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5467.php
www.exploit-db.com/exploits/44676 (ExploitDB-44676)
www.teradek.com (Teradek Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5467.php (Zero Science Lab Disclosure (ZSL-2018-5467))
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.