Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE HVL-A2.0, HVL-A3.0, HVL-A4.0, HVL-AT1.0S, HVL-AT2.0, HVL-AT3.0, HVL-AT4.0, HVL-AT2.0A, HVL-AT3.0A, and HVL-AT4.0A devices with firmware before 2.04 allows remote attackers to hijack the authentication of arbitrary users for requests that delete content.
2016-09-24T10:59:01.243
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | iodata | hvl-a2.0_firmware | 2.03 | Yes |
Operating System | iodata | hvl-a3.0_firmware | 2.03 | Yes |
Operating System | iodata | hvl-a4.0_firmware | 2.03 | Yes |
Operating System | iodata | hvl-at1.0s_firmware | 2.03 | Yes |
Operating System | iodata | hvl-at2.0_firmware | 2.03 | Yes |
Operating System | iodata | hvl-at2.0a_firmware | 2.03 | Yes |
Operating System | iodata | hvl-at3.0_firmware | 2.03 | Yes |
Operating System | iodata | hvl-at3.0a_firmware | 2.03 | Yes |
Operating System | iodata | hvl-at4.0_firmware | 2.03 | Yes |
Operating System | iodata | hvl-at4.0a_firmware | 2.03 | Yes |
Hardware | iodata | hvl-a | - | No |
Hardware | iodata | hvl-at | - | No |
Hardware | iodata | hvl-ata | - | No |