CSRF in Ercom Cryptobox administration console allows attacker to trigger some actions on behalf of a Cryptobox administrator. The attack requires the administrator to browse a malicious web site or to click a link while he has an open session on the administration console.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 17 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 17 Dec 2025 14:00:00 +0000

Type Values Removed Values Added
Description CSRF in Ercom Cryptobox administration console allows attacker to trigger some actions on behalf of a Cryptobox administrator. The attack requires the administrator to browse a malicious web site or to click a link while he has an open session on the administration console.
Title CSRF in Ercom Cryptobox administration console
First Time appeared Ercom
Ercom cryptobox
Weaknesses CWE-352
CPEs cpe:2.3:a:ercom:cryptobox:*:*:*:*:*:*:*:*
Vendors & Products Ercom
Ercom cryptobox
References
Metrics cvssV4_0

{'score': 0.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: THA-PSIRT

Published:

Updated: 2025-12-17T14:18:16.552Z

Reserved: 2025-12-08T13:02:54.031Z

Link: CVE-2025-14266

cve-icon Vulnrichment

Updated: 2025-12-17T14:18:08.546Z

cve-icon NVD

Status : Received

Published: 2025-12-17T14:15:47.563

Modified: 2025-12-17T14:15:47.563

Link: CVE-2025-14266

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses