CVE-2020-12282: Gogogate Ismartgate Pro Firmware

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

iSmartgate PRO 1.5.9 is vulnerable to CSRF via the busca parameter in the form used for searching for users, accessible via /index.php. (This can be combined with reflected XSS.)

Affected products

  • Gogogate Ismartgate Pro Firmware: version 1.5.9 only

Published 2020-09-24. Last modified 2026-06-17.