CVE-2019-18651: 3xlogic Infinias Access Control Firmware
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote attackers to execute malicious and unauthorized actions (e.g., delete application users) by sending a crafted HTML document or encoded URL to a user that the website trusts. The user needs to have an active privileged session.
Affected products
- 3xlogic Infinias Access Control Firmware: up to and including 6.6.9586.0
Published 2019-11-14. Last modified 2026-06-17.