CVE-2024-45372

MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious page while logging in to the web management page of the affected product may lead the user to perform unintended operations such as changing the login password, etc.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:planex:mzk-dp300n_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:planex:mzk-dp300n:-:*:*:*:*:*:*:*

History

03 Oct 2024, 00:34

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Planex mzk-dp300n
Planex mzk-dp300n Firmware
Planex
References () https://jvn.jp/en/jp/JVN81966868/ - () https://jvn.jp/en/jp/JVN81966868/ - Third Party Advisory
References () https://www.planex.co.jp/support/download/mzk-dp300n/ - () https://www.planex.co.jp/support/download/mzk-dp300n/ - Product
CPE cpe:2.3:h:planex:mzk-dp300n:-:*:*:*:*:*:*:*
cpe:2.3:o:planex:mzk-dp300n_firmware:*:*:*:*:*:*:*:*

26 Sep 2024, 13:32

Type Values Removed Values Added
Summary
  • (es) Las versiones de firmware 1.04 y anteriores del MZK-DP300N contienen una vulnerabilidad de cross-site request forgery. Al visualizar una página maliciosa mientras se inicia sesión en la página de administración web del producto afectado, el usuario puede realizar operaciones no deseadas, como cambiar la contraseña de inicio de sesión, etc.

26 Sep 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-26 05:15

Updated : 2024-10-03 00:34


NVD link : CVE-2024-45372

Mitre link : CVE-2024-45372

CVE.ORG link : CVE-2024-45372


JSON object : View

Products Affected

planex

  • mzk-dp300n_firmware
  • mzk-dp300n
CWE
CWE-352

Cross-Site Request Forgery (CSRF)