CVE-2025-67013
MEDIUMDescription
The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin/Referer validation) on critical configuration endpoints.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| etlsystems | d0116s1ula-22454_firmware |
| etlsystems | d0116s1ula-22454 |
| etlsystems | d0116s1uia-22474_firmware |
| etlsystems | d0116s1uia-22474 |
| etlsystems | c0401s1ula-22418_firmware |
| etlsystems | c0401s1ula-22418 |
| etlsystems | c0801s1ula-22420_firmware |
| etlsystems | c0801s1ula-22420 |
| etlsystems | c1601s1ula-22422_firmware |
| etlsystems | c1601s1ula-22422 |
| etlsystems | c0401s1ula-22455_firmware |
| etlsystems | c0401s1ula-22455 |
| etlsystems | c0801s1ula-22457_firmware |
| etlsystems | c0801s1ula-22457 |
| etlsystems | c1601s1ula-22459_firmware |
| etlsystems | c1601s1ula-22459 |
| etlsystems | c1601s1uia-22479_firmware |
| etlsystems | c1601s1uia-22479 |
| etlsystems | d0104d1ula-22411_firmware |
| etlsystems | d0104d1ula-22411 |
| etlsystems | d0108d1ula-22413_firmware |
| etlsystems | d0108d1ula-22413 |
| etlsystems | d0104d1ula-22451_firmware |
| etlsystems | d0104d1ula-22451 |
| etlsystems | d0108d1ula-22453_firmware |
| etlsystems | d0108d1ula-22453 |
| etlsystems | d0108d1uia-22473_firmware |
| etlsystems | d0108d1uia-22473 |
| etlsystems | c0401d1ula-22419_firmware |
| etlsystems | c0401d1ula-22419 |
| etlsystems | c0801d1ula-22421_firmware |
| etlsystems | c0801d1ula-22421 |
| etlsystems | c0401d1ula-22456_firmware |
| etlsystems | c0401d1ula-22456 |
| etlsystems | c0801d1ula-22458_firmware |
| etlsystems | c0801d1ula-22458 |
| etlsystems | c0401d1uia-22476_firmware |
| etlsystems | c0401d1uia-22476 |
| etlsystems | h0108d1ula-22431_firmware |
| etlsystems | h0108d1ula-22431 |
| etlsystems | h0104d1ula-22460_firmware |
| etlsystems | h0104d1ula-22460 |
| etlsystems | h0108d1ula-22461_firmware |
| etlsystems | h0108d1ula-22461 |
| etlsystems | d0104s1ula-22410_firmware |
| etlsystems | d0104s1ula-22410 |
| etlsystems | d0108s1ula-22412_firmware |
| etlsystems | d0108s1ula-22412 |
| etlsystems | d0116s1ula-22414_firmware |
| etlsystems | d0116s1ula-22414 |
| etlsystems | d0104s1ula-22450_firmware |
| etlsystems | d0104s1ula-22450 |
| etlsystems | d0108s1ula-22452_firmware |
| etlsystems | d0108s1ula-22452 |
References
Frequently Asked Questions
What is CVE-2025-67013? +
How severe is CVE-2025-67013? +
What products are affected by CVE-2025-67013? +
How do I check if I'm vulnerable to CVE-2025-67013? +
Related Vulnerabilities
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the `cTrash.restore` function does …
Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cUsers.updateAddress function does …
Websites managed by MegaBIP in versions below 5.15 are vulnerable to Cross-Site Request Forgery (CSRF) as the form available under …
Emlog is an open source website building system. Prior to version 2.6.11, missing CSRF protection in critical admin functions allows …
Versions of Gliffy Online prior to versions 4.14.0-7 contains a Cross Site Request Forgery (CSRF) flaw.