Description
Mercku M6a devices through 2.1.0 allow password changes via intranet CSRF attacks.
Problem types
CWE-352 Cross-Site Request Forgery (CSRF)
Product status
Any version
References
seclists.org/fulldisclosure/2025/Oct/10
blog.nullvoid.me/posts/mercku-exploits/