CVE-2026-29521

Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a cross-site request forgery vulnerability that allows attackers to modify device configuration by exploiting missing CSRF protections in setup.cgi. Attackers can host malicious pages that submit forged requests using automatically-included HTTP Basic Authentication credentials to add RADIUS accounts, alter network settings, or trigger diagnostics.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hereta:eth-imc408m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hereta:eth-imc408m:-:*:*:*:*:*:*:*

History

10 Apr 2026, 17:42

Type Values Removed Values Added
Summary
  • (es) Hereta ETH-IMC408M firmware versión 1.0.15 y anteriores contienen una vulnerabilidad de falsificación de petición en sitios cruzados que permite a los atacantes modificar la configuración del dispositivo explotando la falta de protecciones CSRF en setup.cgi. Los atacantes pueden alojar páginas maliciosas que envían peticiones falsificadas utilizando credenciales de autenticación básica HTTP incluidas automáticamente para añadir cuentas RADIUS, alterar la configuración de red o activar diagnósticos.
First Time Hereta eth-imc408m Firmware
Hereta eth-imc408m
Hereta
References () https://web.archive.org/web/20250820105319/http://hereta.com/ - () https://web.archive.org/web/20250820105319/http://hereta.com/ - Product
References () https://www.vulncheck.com/advisories/hereta-eth-imc408m-csrf-via-configuration-setup - () https://www.vulncheck.com/advisories/hereta-eth-imc408m-csrf-via-configuration-setup - Third Party Advisory
CPE cpe:2.3:h:hereta:eth-imc408m:-:*:*:*:*:*:*:*
cpe:2.3:o:hereta:eth-imc408m_firmware:*:*:*:*:*:*:*:*

17 Mar 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

16 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 18:16

Updated : 2026-04-10 17:42


NVD link : CVE-2026-29521

Mitre link : CVE-2026-29521

CVE.ORG link : CVE-2026-29521


JSON object : View

Products Affected

hereta

  • eth-imc408m_firmware
  • eth-imc408m
CWE
CWE-352

Cross-Site Request Forgery (CSRF)