Cross-site request forgery vulnerability exists in Web Caster V130 versions 1.08 and earlier. If a logged-in user views a malicious page created by an attacker, the settings of the product may be unintentionally changed.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-26635 Cross-site request forgery vulnerability exists in Web Caster V130 versions 1.08 and earlier. If a logged-in user views a malicious page created by an attacker, the settings of the product may be unintentionally changed.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 03 Sep 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ntt-east
Ntt-east web Caster
Ntt-west
Ntt-west web Caster
Vendors & Products Ntt-east
Ntt-east web Caster
Ntt-west
Ntt-west web Caster

Wed, 03 Sep 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Sep 2025 05:45:00 +0000

Type Values Removed Values Added
Description Cross-site request forgery vulnerability exists in Web Caster V130 versions 1.08 and earlier. If a logged-in user views a malicious page created by an attacker, the settings of the product may be unintentionally changed.
Weaknesses CWE-352
References
Metrics cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2025-09-03T19:50:59.498Z

Reserved: 2025-08-27T23:47:30.395Z

Link: CVE-2025-58272

cve-icon Vulnrichment

Updated: 2025-09-03T19:50:55.008Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-03T06:15:50.613

Modified: 2025-09-04T15:36:56.447

Link: CVE-2025-58272

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-03T20:26:55Z