The #usdHeroLab analysts examined the application #MultiTech Conduit AP MTCAP2-L4E1 while conducting their security analyses.
1⃣ Vulnerability Type: cross-site request forgery attacks (CSRF)
🚨Security Risk: High
👇 More details
🧐MultiTech Conduit AP MTCAP2-L4E1 is a LoRaWAN access point to provide connectivity of IoT assets. The webinterface allows configuration of settings like user management, LoRaWAN, Firewall and custom applications.
The vulnerability can be used to perform actions on other users behalf which may result in remote code execution.
The vulnerability was reported to the vendor under the Responsible Disclosure Policy and subsequently fixed for #moresecurity. More information can be found here 👨💻👩💻👇
https://herolab.usd.de/en/security-advisories/usd-2023-0004/