Cross-Site Request Forgery Vulnerability in TOSHIBA TEC e-Studio Devices
CVE-2014-1990
Currently unrated
Key Information:
- Vendor
Toshiba
- Vendor
- CVE Published:
- 19 April 2014
What is CVE-2014-1990?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the web-based management utility of TOSHIBA TEC e-Studio 232, 233, 282, and 283 devices. This flaw allows remote attackers to exploit the authentication process of administrators, enabling them to perform unauthorized actions, such as changing passwords, without consent. By tricking an administrator into clicking a malicious link while logged in, attackers can hijack their session and execute commands on their behalf, posing significant security risks to sensitive systems.