Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://info.cryptobox.com/doc/v4.39/4.39.en/#fix2 |
|
Wed, 17 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 17 Dec 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CSRF in Ercom Cryptobox administration console allows attacker to trigger some actions on behalf of a Cryptobox administrator. The attack requires the administrator to browse a malicious web site or to click a link while he has an open session on the administration console. | |
| Title | CSRF in Ercom Cryptobox administration console | |
| First Time appeared |
Ercom
Ercom cryptobox |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:ercom:cryptobox:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ercom
Ercom cryptobox |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: THA-PSIRT
Published:
Updated: 2025-12-17T14:18:16.552Z
Reserved: 2025-12-08T13:02:54.031Z
Link: CVE-2025-14266
Updated: 2025-12-17T14:18:08.546Z
Status : Deferred
Published: 2025-12-17T14:15:47.563
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-14266
No data.
OpenCVE Enrichment
No data.