Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 10 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hereta
Hereta eth-imc408m Hereta eth-imc408m Firmware |
|
| CPEs | cpe:2.3:h:hereta:eth-imc408m:-:*:*:*:*:*:*:* cpe:2.3:o:hereta:eth-imc408m_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Hereta
Hereta eth-imc408m Hereta eth-imc408m Firmware |
Tue, 17 Mar 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 17 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shenzhen Hereta Technology
Shenzhen Hereta Technology hereta Eth-imc408m |
|
| Vendors & Products |
Shenzhen Hereta Technology
Shenzhen Hereta Technology hereta Eth-imc408m |
Mon, 16 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a cross-site request forgery vulnerability that allows attackers to modify device configuration by exploiting missing CSRF protections in setup.cgi. Attackers can host malicious pages that submit forged requests using automatically-included HTTP Basic Authentication credentials to add RADIUS accounts, alter network settings, or trigger diagnostics. | |
| Title | Hereta ETH-IMC408M CSRF via Configuration Setup | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-17T15:29:46.810Z
Reserved: 2026-03-04T15:39:26.873Z
Link: CVE-2026-29521
Updated: 2026-03-16T18:11:00.428Z
Status : Analyzed
Published: 2026-03-16T18:16:08.500
Modified: 2026-04-10T17:42:56.420
Link: CVE-2026-29521
No data.
OpenCVE Enrichment
Updated: 2026-04-13T14:28:31Z