KYOCERA Net Admin 3.4.0906 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can craft malicious web pages that automatically submit forms to add new admin accounts with predefined credentials when a logged-in user visits the page.
Metrics
Affected Vendors & Products
References
History
Wed, 24 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | KYOCERA Net Admin 3.4.0906 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can craft malicious web pages that automatically submit forms to add new admin accounts with predefined credentials when a logged-in user visits the page. | |
| Title | KYOCERA Net Admin 3.4.0906 Cross-Site Request Forgery via User Administration | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-24T20:21:49.801Z
Reserved: 2025-12-24T14:27:12.478Z
Link: CVE-2019-25254
Updated: 2025-12-24T20:01:22.076Z
Status : Received
Published: 2025-12-24T20:15:54.010
Modified: 2025-12-24T21:16:03.503
Link: CVE-2019-25254
No data.
OpenCVE Enrichment
No data.