cbcvebase.
CVE-2020-7503
published 2020-06-16

CVE-2020-7503: A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to execute…

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to execute malicious commands on behalf of a legitimate user when xsrf-token data is intercepted.

Affected

1 ranges
VendorProductVersion rangeFixed in
schneider-electriceasergy_t300_firmware<= 1.5.2