CVE-2026-22323
published 2026-03-18CVE-2026-22323: A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick authenticated users into sending…
PriorityP339high7.1CVSS 3.1
AVNACLPRNUIRSUCNIHAL
EPSS
0.18%
7.6th percentile
A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick authenticated users into sending unauthorized POST requests to the device by luring them to a malicious webpage. This can silently alter the device’s configuration without the victim’s knowledge or consent. Availability impact was set to low because after a successful attack the device will automatically recover without external intervention.
Affected
77 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phoenix_contact | fl_nat_2008 | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_nat_2208 | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_nat_2304-2gc-2sfp | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2005 | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2008 | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2008f | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2016 | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2105 | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2108 | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2116 | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2204-2tc-2sfx | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2205 | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2206-2fx | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2206-2fx_sm | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2206-2fx_sm_st | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2206-2fx_st | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2206-2sfx | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2206-2sfx_pn | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2206c-2fx | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2207-fx | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2207-fx_sm | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2208 | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2208_pn | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2208c | >= 0.0.0 < 3.53 | 3.53 |
| phoenix_contact | fl_switch_2212-2tc-2sfx | >= 0.0.0 < 3.53 | 3.53 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-03-18
Published