CVE-2022-22811: CSRF
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could induce users to perform unintended actions, leading to the override of the system?s configurations when an attacker persuades a user to visit a rogue website. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior)
Other sources
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could induce users to perform unintended actions, leading to the override of the system�s configurations when an attacker persuades a user to visit a rogue website. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior)
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-22811?
CVE-2022-22811 refers to a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to induce users to perform unintended actions.
How does CVE-2022-22811 work?
CVE-2022-22811 works by persuading a user to visit a rogue website, which can lead to the override of the system's configurations.
What is the severity of CVE-2022-22811?
CVE-2022-22811 has a severity rating of 8.1 which is considered high.
Which products are affected by CVE-2022-22811?
CVE-2022-22811 affects spaceLYnk (V2.6.2 and prior), Wiser for KNX (V2.6.2 and prior), and Fellerlynk (V2.6.2 and prior) firmware.
How can I fix CVE-2022-22811?
To fix CVE-2022-22811, it is recommended to update affected products to a version that has addressed the CSRF vulnerability.