A Cross-Site Request Forgery (CSRF) issue was discovered in Westermo MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The application does not verify whether a request was intentionally provided by the user, making it possible for an attacker to trick a user into making a malicious request to the server.
2017-08-25T16:29:00.237
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | westermo | mrd-305-din_firmware | - | Yes |
Hardware | westermo | mrd-305-din | - | No |
Operating System | westermo | mrd-315-din_firmware | - | Yes |
Hardware | westermo | mrd-315-din | - | No |
Operating System | westermo | mrd-355-din_firmware | - | Yes |
Hardware | westermo | mrd-355-din | - | No |
Operating System | westermo | mrd-455-din_firmware | - | Yes |
Hardware | westermo | mrd-455-din | - | No |