Description
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior lack CSRF protections for state-changing actions in the administrative interface. An attacker can trick an authenticated administrator into performing unauthorized configuration changes.
Problem types
CWE-352 Cross-Site Request Forgery (CSRF)
Product status
Any version
Credits
Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.
References
www.binardat.com/...al-fanless-fiber-binardat-network-switch
www.vulncheck.com/...ardat-10g08-0800gsm-network-switch-csrf