ETIC Telecom Remote Access Server Cross-Site Request Forgery Vulnerability

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in ETIC Telecom Remote Access Server (RAS) versions prior to 4.9.19. This vulnerability allows an external attacker to manipulate an end user into sending a 'setconf' method request without the need for a CSRF token, potentially causing a denial-of-service condition on the device.

Impact

Exploitation of this vulnerability can lead to a denial-of-service condition on the affected device.

Remediation

Users are advised to update ETIC Telecom Remote Access Server to version 4.9.19 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
6.5
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.