CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-26153: ETIC Telecom Remote Access Server (RAS) Cross-Site Request Forgery

7.4 CVSS

Description

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19
are vulnerable to cross-site request forgery (CSRF). An external
attacker with no access to the device can force the end user into
submitting a "setconf" method request, not requiring any CSRF token,
which can lead into denial of service on the device.

Classification

CVE ID: CVE-2024-26153

CVSS Base Severity: HIGH

CVSS Base Score: 7.4

Affected Products

Vendor: ETIC Telecom

Product: Remote Access Server (RAS)

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.66% (scored less or equal to compared to others)

EPSS Date: 2025-02-15 (when was this score calculated)

References

https://www.cisa.gov/news-events/ics-advisories/icsa-22-307-01

Timeline