CVE-2024-45372

MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious page while logging in to the web management page of the affected product may lead the user to perform unintended operations such as changing the login password, etc.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:planex:mzk-dp300n_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:planex:mzk-dp300n:-:*:*:*:*:*:*:*

History

03 Oct 2024, 00:34

Type Values Removed Values Added
References () https://www.planex.co.jp/support/download/mzk-dp300n/ - () https://www.planex.co.jp/support/download/mzk-dp300n/ - Product
References () https://jvn.jp/en/jp/JVN81966868/ - () https://jvn.jp/en/jp/JVN81966868/ - Third Party Advisory
First Time Planex mzk-dp300n
Planex mzk-dp300n Firmware
Planex
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:o:planex:mzk-dp300n_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:planex:mzk-dp300n:-:*:*:*:*:*:*:*
CWE CWE-352

26 Sep 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-26 05:15

Updated : 2025-03-25 16:15


NVD link : CVE-2024-45372

Mitre link : CVE-2024-45372


JSON object : View

Products Affected

planex

  • mzk-dp300n_firmware
  • mzk-dp300n
CWE
CWE-352

Cross-Site Request Forgery (CSRF)