Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto NX3020 1.8.3.0, Nexto NX3030 1.8.3.0, Nexto NX5100 1.8.11.0, Nexto NX5101 1.8.11.0, Nexto NX5110 1.1.2.8, Nexto NX5210 1.1.2.8, Nexto Xpress XP300 1.8.11.0, Nexto Xpress XP315 1.8.11.0, Nexto Xpress XP325 1.8.11.0, Nexto Xpress XP340 1.8.11.0, and Hadron Xtorm HX3040 1.7.58.0.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Altus
Subscribe
|
Hadron Xtorm Hx3040
Subscribe
Hadron Xtorm Hx3040 Firmware
Subscribe
Nexto Nx3003
Subscribe
Nexto Nx3003 Firmware
Subscribe
Nexto Nx3004
Subscribe
Nexto Nx3004 Firmware
Subscribe
Nexto Nx3005
Subscribe
Nexto Nx3005 Firmware
Subscribe
Nexto Nx3010
Subscribe
Nexto Nx3010 Firmware
Subscribe
Nexto Nx3020
Subscribe
Nexto Nx3020 Firmware
Subscribe
Nexto Nx3030
Subscribe
Nexto Nx3030 Firmware
Subscribe
Nexto Nx5100
Subscribe
Nexto Nx5100 Firmware
Subscribe
Nexto Nx5101
Subscribe
Nexto Nx5101 Firmware
Subscribe
Nexto Nx5110
Subscribe
Nexto Nx5110 Firmware
Subscribe
Nexto Nx5210
Subscribe
Nexto Nx5210 Firmware
Subscribe
Nexto Xpress Xp300
Subscribe
Nexto Xpress Xp300 Firmware
Subscribe
Nexto Xpress Xp315
Subscribe
Nexto Xpress Xp315 Firmware
Subscribe
Nexto Xpress Xp325
Subscribe
Nexto Xpress Xp325 Firmware
Subscribe
Nexto Xpress Xp340
Subscribe
Nexto Xpress Xp340 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-25605 | Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto NX3020 1.8.3.0, Nexto NX3030 1.8.3.0, Nexto NX5100 1.8.11.0, Nexto NX5101 1.8.11.0, Nexto NX5110 1.1.2.8, Nexto NX5210 1.1.2.8, Nexto Xpress XP300 1.8.11.0, Nexto Xpress XP315 1.8.11.0, Nexto Xpress XP325 1.8.11.0, Nexto Xpress XP340 1.8.11.0, and Hadron Xtorm HX3040 1.7.58.0. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T02:06:40.806Z
Reserved: 2021-08-17T00:00:00
Link: CVE-2021-39243
No data.
Status : Modified
Published: 2021-08-23T05:15:08.237
Modified: 2024-11-21T06:19:00.067
Link: CVE-2021-39243
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD