Unibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF) vulnerability in /tools/network-trace, /list_users, /list_byod?usertyperaduser, /dhcp_leases, /go?rid202 in which a specially crafted HTTP request may reconfigure the device.
Publication date: Fri, 09 Apr 2021 18:15:00 +0000