CVE-2025-67013
CSRF Vulnerability in ETL Systems DEXTRA Web Interface
Publication date: 2025-12-26
Last updated on: 2025-12-26
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| etl_systems_ltd | dextra_series | 1.8 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the web management interface of ETL Systems Ltd DEXTRA Series Digital L-Band Distribution System v1.8. It lacks Cross-Site Request Forgery (CSRF) protection mechanisms, such as tokens or Origin/Referer validation, on critical configuration endpoints. This means that an attacker could potentially trick an authenticated user into executing unwanted actions on the system without their consent.
How can this vulnerability impact me? :
The lack of CSRF protection on critical configuration endpoints can allow attackers to perform unauthorized actions on the device by exploiting an authenticated user's session. This could lead to unauthorized changes in system configuration, potentially disrupting service or compromising the security of the system.