Cross-Site Request Forgery in Ericsson Indoor Connect 8855
CVE-2025-40841

5.1MEDIUM

Key Information:

Vendor

Ericsson

Vendor
CVE Published:
25 March 2026

What is CVE-2025-40841?

The Ericsson Indoor Connect 8855 prior to version 2025.Q3 is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. This security flaw allows an attacker to exploit the system, potentially resulting in the unauthorized modification of sensitive information. Users are advised to update their systems to the latest version to mitigate risks associated with this vulnerability.

Affected Version(s)

Indoor Connect 8855 0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Telstra
.