CVE-2025-67013

EUVD-2025-205447
The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin/Referer validation) on critical configuration endpoints.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CISA-ADPADP
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
etlsystemsd0116s1ula-22454_firmware
1.8
etlsystemsd0116s1uia-22474_firmware
1.8
etlsystemsc0401s1ula-22418_firmware
1.8
etlsystemsc0801s1ula-22420_firmware
1.8
etlsystemsc1601s1ula-22422_firmware
1.8
etlsystemsc0401s1ula-22455_firmware
1.8
etlsystemsc0801s1ula-22457_firmware
1.8
etlsystemsc1601s1ula-22459_firmware
1.8
etlsystemsc1601s1uia-22479_firmware
1.8
etlsystemsd0104d1ula-22411_firmware
1.8
etlsystemsd0108d1ula-22413_firmware
1.8
etlsystemsd0104d1ula-22451_firmware
1.8
etlsystemsd0108d1ula-22453_firmware
1.8
etlsystemsd0108d1uia-22473_firmware
1.8
etlsystemsc0401d1ula-22419_firmware
1.8
etlsystemsc0801d1ula-22421_firmware
1.8
etlsystemsc0401d1ula-22456_firmware
1.8
etlsystemsc0801d1ula-22458_firmware
1.8
etlsystemsc0401d1uia-22476_firmware
1.8
etlsystemsh0108d1ula-22431_firmware
1.8
etlsystemsh0104d1ula-22460_firmware
1.8
etlsystemsh0108d1ula-22461_firmware
1.8
etlsystemsd0104s1ula-22410_firmware
1.8
etlsystemsd0108s1ula-22412_firmware
1.8
etlsystemsd0116s1ula-22414_firmware
1.8
etlsystemsd0104s1ula-22450_firmware
1.8
etlsystemsd0108s1ula-22452_firmware
1.8
𝑥
= Vulnerable software versions