Cross-Site Request Forgery Vulnerability in JM-DATA ONU JF511-TV
CVE-2022-50804
Key Information:
- Vendor
Jm-data Onu
- Status
- Vendor
- CVE Published:
- 30 December 2025
Badges
What is CVE-2022-50804?
The JM-DATA ONU JF511-TV version 1.0.67 is susceptible to cross-site request forgery (CSRF) attacks. This vulnerability enables malicious actors to execute administrative tasks on behalf of authenticated users without their awareness or approval. Exploitation of this flaw may involve sending crafted requests that manipulate the user's session, potentially compromising sensitive configurations and permitting unauthorized access to the device's administrative functions.
Affected Version(s)
JF511-TV 1.0.67
JF511-TV 1.0.62
JF511-TV 1.0.55
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
