JM-DATA ONU JF511-TV Cross-Site Request Forgery Vulnerability

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in the JM-DATA ONU JF511-TV, affecting versions 1.0.67, 1.0.62, and 1.0.55. This vulnerability allows attackers to perform administrative actions on behalf of authenticated users without their knowledge or consent. The issue arises from improper validation of user input on the '/boaform/admin/formURL' endpoint.

Impact

Exploitation of this vulnerability could lead to unauthorized administrative actions being performed on behalf of users, potentially allowing for cross-site scripting (XSS) attacks, web cache poisoning, and other malicious activities.

Reproduction

To reproduce this vulnerability, an attacker must persuade an authenticated user to visit a malicious website. Once the user is tricked into visiting the site, the attacker can send a crafted HTTP request that exploits the CSRF vulnerability. This can be done by using a form that submits to the '/boaform/admin/formURL' endpoint with the appropriate parameters to perform the desired administrative action, such as deleting an IP entry filter.

Added: Dec 30, 2025, 11:28 PM
Updated: Dec 30, 2025, 11:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.7
remediation
0.0
relevance
1.8
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.