Home
HIGH: 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HDefault status
unaffected
Any version before V1.49
affected
Default status
unaffected
Any version before V1.62
affected
Default status
unaffected
Any version before V1.62
affected
Description
An unauthenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of Cross-Site Request Forgery (CSRF) protection.
Problem types
CWE-352 Cross-Site Request Forgery (CSRF)
Product status
Any version before V1.49
Any version before V1.62
Any version before V1.62
Credits
ONEKEY Research Labs
References
certvde.com/en/advisories/VDE-2025-052