Ad

CVE-2026-1835

MEDIUM CVSS 4.0: 5.3 EPSS 0.01%
Updated Feb 04, 2026
Parameter Value
CVSS 5.3 (MEDIUM)
Type CWE-862 (Missing Authorization (Отсутствие авторизации)), CWE-352 (Cross-Site Request Forgery (CSRF) (Подделка межсайтовых запросов))
Public PoC No

A vulnerability was identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. This affects an unknown part. The manipulation leads to cross-site request forgery.

The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery.

Therefore, version details for affected or updated releases cannot be specified.

Attack Parameters

Attack Vector
Network
Атака возможна удалённо
Attack Complexity
Low
Легко эксплуатировать
Attack Requirements
None
Нет дополнительных условий
Privileges Required
None
Права не нужны
User Interaction
Passive
Минимальное взаимодействие

Impact Assessment

Confidentiality
None
Нет утечки данных
Integrity
Low
Частичная модификация данных
Availability
None
Нет нарушения работы

CVSS Vector v4.0