Cross-Site Request Forgery in Schneider Electric SpaceLYnk and Wiser for KNX
CVE-2022-22811
8.1HIGH
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 9 February 2022
What is CVE-2022-22811?
A Cross-Site Request Forgery (CSRF) vulnerability in Schneider Electric's spaceLYnk, Wiser for KNX, and fellerLYnk products allows malicious actors to trick users into executing unintended commands. By luring users to a fraudulent website, an attacker could manipulate configurations and settings without direct interaction with the systems, leading to potential system misconfigurations and security lapses.
Affected Version(s)
spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior) spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior)