CVE-2024-45372

Published Sep 26, 2024

Last updated a month ago

Overview

Description
MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious page while logging in to the web management page of the affected product may lead the user to perform unintended operations such as changing the login password, etc.
Source
vultures@jpcert.or.jp
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
6.5
Impact score
3.6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Severity
MEDIUM

Weaknesses

vultures@jpcert.or.jp
CWE-352
nvd@nist.gov
CWE-352

Social media

Hype score
Not currently trending

Configurations