CVE-2017-12126: CSRF
An exploitable cross-site request forgery vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP packet can cause cross-site request forgery. An attacker can create malicious HTML to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12126?
CVE-2017-12126 is classified as a high severity cross-site request forgery vulnerability.
How do I fix CVE-2017-12126?
To mitigate CVE-2017-12126, update the Moxa EDR-810 firmware to the latest version available from the vendor.
What systems are affected by CVE-2017-12126?
CVE-2017-12126 affects the Moxa EDR-810 firmware version 4.1.
What kind of attacks can exploit CVE-2017-12126?
CVE-2017-12126 can be exploited by an attacker using specially crafted HTTP packets to perform cross-site request forgery.
Can CVE-2017-12126 be exploited remotely?
Yes, CVE-2017-12126 can be exploited remotely if an attacker tricks a user into loading a malicious HTML page.