Teradek Cube 7.3.6 CSRF Change...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Summary Cube packs world-class video quality into a rugged, portable chassis for quick IP video deployments at any location. Each encoder and decoder includes HDMI and 3G-SDI I/O, Ethernet / WiFI connectivity, and full duplex IFB. ### Description The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site. ### Vendor Teradek, LLC - https://www.teradek.com ### Affected Version * Firmware Version: 7.3.6 (build 26850) * Hardware Version: 1.5 * Teradek Firmware Version 7.3.15 ### Tested On * lighttpd/1.4.31

0%
暂无可用Exp或PoC
当前有0条受影响产品信息