Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-424f-g622-9cvv

Опубликовано: 16 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 5.3

Описание

Ubee EVW327 contains a cross-site request forgery vulnerability that allows attackers to enable remote access without user interaction. Attackers can craft a malicious webpage that automatically submits a form to change router remote access settings to port 8080 without the user's consent.

Ubee EVW327 contains a cross-site request forgery vulnerability that allows attackers to enable remote access without user interaction. Attackers can craft a malicious webpage that automatically submits a form to change router remote access settings to port 8080 without the user's consent.

EPSS

Процентиль: 4%
0.00018
Низкий

5.1 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 5.3
nvd
22 дня назад

Ubee EVW327 contains a cross-site request forgery vulnerability that allows attackers to enable remote access without user interaction. Attackers can craft a malicious webpage that automatically submits a form to change router remote access settings to port 8080 without the user's consent.

EPSS

Процентиль: 4%
0.00018
Низкий

5.1 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-352