Vulnerability Description
JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to cross-site request forgery (CSRF) attacks, allowing attackers to perform administrative actions on behalf of authenticated users without their knowledge or consent.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jm-Data | Onu Jf511-Tv Firmware | 1.0.55 |
| Jm-Data | Onu Jf511-Tv | - |
Related Weaknesses (CWE)
References
- https://cxsecurity.com/issue/WLB-2022060058ExploitThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/229355Third Party Advisory
- https://packetstormsecurity.com/files/167487/Third Party Advisory
- https://www.jm-data.com/Product
- https://www.vulncheck.com/advisories/jm-data-onu-jf-tv-cross-site-request-forgerThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5708.phpThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5708.phpThird Party Advisory
FAQ
What is CVE-2022-50804?
CVE-2022-50804 is a vulnerability with a CVSS score of 8.8 (HIGH). JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to cross-site request forgery (CSRF) attacks, allowing attackers to perform administrative actions on behalf of authenticated users without their know...
How severe is CVE-2022-50804?
CVE-2022-50804 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-50804?
Check the references section above for vendor advisories and patch information. Affected products include: Jm-Data Onu Jf511-Tv Firmware, Jm-Data Onu Jf511-Tv.