CVE-2025-67013
Unknown Unknown - Not Provided
CSRF Vulnerability in ETL Systems DEXTRA Web Interface

Publication date: 2025-12-26

Last updated on: 2025-12-26

Assigner: MITRE

Description
The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin/Referer validation) on critical configuration endpoints.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-26
Last Modified
2025-12-26
Generated
2026-05-07
AI Q&A
2025-12-26
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
etl_systems_ltd dextra_series 1.8
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in the web management interface of ETL Systems Ltd DEXTRA Series Digital L-Band Distribution System v1.8. It lacks Cross-Site Request Forgery (CSRF) protection mechanisms, such as tokens or Origin/Referer validation, on critical configuration endpoints. This means that an attacker could potentially trick an authenticated user into executing unwanted actions on the system without their consent.


How can this vulnerability impact me? :

The lack of CSRF protection on critical configuration endpoints can allow attackers to perform unauthorized actions on the device by exploiting an authenticated user's session. This could lead to unauthorized changes in system configuration, potentially disrupting service or compromising the security of the system.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart