MEDIUM · 6.5

CVE-2025-67013

The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin...

Vulnerability Description

The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin/Referer validation) on critical configuration endpoints.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
EtlsystemsD0116S1Ula-22454 Firmware1.8
EtlsystemsD0116S1Ula-22454-
EtlsystemsD0116S1Uia-22474 Firmware1.8
EtlsystemsD0116S1Uia-22474-
EtlsystemsC0401S1Ula-22418 Firmware1.8
EtlsystemsC0401S1Ula-22418-
EtlsystemsC0801S1Ula-22420 Firmware1.8
EtlsystemsC0801S1Ula-22420-
EtlsystemsC1601S1Ula-22422 Firmware1.8
EtlsystemsC1601S1Ula-22422-
EtlsystemsC0401S1Ula-22455 Firmware1.8
EtlsystemsC0401S1Ula-22455-
EtlsystemsC0801S1Ula-22457 Firmware1.8
EtlsystemsC0801S1Ula-22457-
EtlsystemsC1601S1Ula-22459 Firmware1.8
EtlsystemsC1601S1Ula-22459-
EtlsystemsC1601S1Uia-22479 Firmware1.8
EtlsystemsC1601S1Uia-22479-
EtlsystemsD0104D1Ula-22411 Firmware1.8
EtlsystemsD0104D1Ula-22411-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-67013?

CVE-2025-67013 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin...

How severe is CVE-2025-67013?

CVE-2025-67013 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-67013?

Check the references section above for vendor advisories and patch information. Affected products include: Etlsystems D0116S1Ula-22454 Firmware, Etlsystems D0116S1Ula-22454, Etlsystems D0116S1Uia-22474 Firmware, Etlsystems D0116S1Uia-22474, Etlsystems C0401S1Ula-22418 Firmware.