CVE-2025-67013

MEDIUM
Published Dec 26, 2025 Modified Jan 2, 2026 CWE-352

Description

The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin/Referer validation) on critical configuration endpoints.

CVSS v3.1 Score

6.5
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Weakness Type (CWE)

CWE-352 Cross-Site Request Forgery

Affected Products

Vendor Product
etlsystems d0116s1ula-22454_firmware
etlsystems d0116s1ula-22454
etlsystems d0116s1uia-22474_firmware
etlsystems d0116s1uia-22474
etlsystems c0401s1ula-22418_firmware
etlsystems c0401s1ula-22418
etlsystems c0801s1ula-22420_firmware
etlsystems c0801s1ula-22420
etlsystems c1601s1ula-22422_firmware
etlsystems c1601s1ula-22422
etlsystems c0401s1ula-22455_firmware
etlsystems c0401s1ula-22455
etlsystems c0801s1ula-22457_firmware
etlsystems c0801s1ula-22457
etlsystems c1601s1ula-22459_firmware
etlsystems c1601s1ula-22459
etlsystems c1601s1uia-22479_firmware
etlsystems c1601s1uia-22479
etlsystems d0104d1ula-22411_firmware
etlsystems d0104d1ula-22411
etlsystems d0108d1ula-22413_firmware
etlsystems d0108d1ula-22413
etlsystems d0104d1ula-22451_firmware
etlsystems d0104d1ula-22451
etlsystems d0108d1ula-22453_firmware
etlsystems d0108d1ula-22453
etlsystems d0108d1uia-22473_firmware
etlsystems d0108d1uia-22473
etlsystems c0401d1ula-22419_firmware
etlsystems c0401d1ula-22419
etlsystems c0801d1ula-22421_firmware
etlsystems c0801d1ula-22421
etlsystems c0401d1ula-22456_firmware
etlsystems c0401d1ula-22456
etlsystems c0801d1ula-22458_firmware
etlsystems c0801d1ula-22458
etlsystems c0401d1uia-22476_firmware
etlsystems c0401d1uia-22476
etlsystems h0108d1ula-22431_firmware
etlsystems h0108d1ula-22431
etlsystems h0104d1ula-22460_firmware
etlsystems h0104d1ula-22460
etlsystems h0108d1ula-22461_firmware
etlsystems h0108d1ula-22461
etlsystems d0104s1ula-22410_firmware
etlsystems d0104s1ula-22410
etlsystems d0108s1ula-22412_firmware
etlsystems d0108s1ula-22412
etlsystems d0116s1ula-22414_firmware
etlsystems d0116s1ula-22414
etlsystems d0104s1ula-22450_firmware
etlsystems d0104s1ula-22450
etlsystems d0108s1ula-22452_firmware
etlsystems d0108s1ula-22452

References

Frequently Asked Questions

What is CVE-2025-67013? +
The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin/Referer validation) on critical configuration endpoints. It has a CVSS v3.1 base score of 6.5 (MEDIUM).
How severe is CVE-2025-67013? +
CVE-2025-67013 has a CVSS v3.1 score of 6.5 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2025-67013? +
CVE-2025-67013 affects products from etlsystems, specifically: c0401d1uia-22476, c0401d1uia-22476_firmware, c0401d1ula-22419, c0401d1ula-22419_firmware, c0401d1ula-22456, c0401d1ula-22456_firmware, c0401s1ula-22418, c0401s1ula-22418_firmware, c0401s1ula-22455, c0401s1ula-22455_firmware, c0801d1ula-22421, c0801d1ula-22421_firmware, c0801d1ula-22458, c0801d1ula-22458_firmware, c0801s1ula-22420, c0801s1ula-22420_firmware, c0801s1ula-22457, c0801s1ula-22457_firmware, c1601s1uia-22479, c1601s1uia-22479_firmware, c1601s1ula-22422, c1601s1ula-22422_firmware, c1601s1ula-22459, c1601s1ula-22459_firmware, d0104d1ula-22411, d0104d1ula-22411_firmware, d0104d1ula-22451, d0104d1ula-22451_firmware, d0104s1ula-22410, d0104s1ula-22410_firmware, d0104s1ula-22450, d0104s1ula-22450_firmware, d0108d1uia-22473, d0108d1uia-22473_firmware, d0108d1ula-22413, d0108d1ula-22413_firmware, d0108d1ula-22453, d0108d1ula-22453_firmware, d0108s1ula-22412, d0108s1ula-22412_firmware, d0108s1ula-22452, d0108s1ula-22452_firmware, d0116s1uia-22474, d0116s1uia-22474_firmware, d0116s1ula-22414, d0116s1ula-22414_firmware, d0116s1ula-22454, d0116s1ula-22454_firmware, h0104d1ula-22460, h0104d1ula-22460_firmware, h0108d1ula-22431, h0108d1ula-22431_firmware, h0108d1ula-22461, h0108d1ula-22461_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2025-67013? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2025-67013 — free, no signup required.

Start Free Scan