Cross-Site Request Forgery Vulnerability in Sierra Wireless AirLink Devices
CVE-2017-6042
What is CVE-2017-6042?
A Cross-Site Request Forgery (CSRF) vulnerability exists in Sierra Wireless AirLink Raven XE and Raven XT devices, where the system fails to verify if incoming requests are legitimate and initiated by the authenticated user. This flaw enables an attacker to exploit the device by tricking a logged-in user into executing unintended requests, potentially leading to unauthorized actions on the web server without the user's knowledge. Users are encouraged to update to the latest firmware versions to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Sierra Wireless AirLink Raven XE and XT Sierra Wireless AirLink Raven XE and XT
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
