CVE-2023-38579: Westermo l206-f2g Firmware

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

The cross-site request forgery token in the request may be predictable or easily guessable allowing attackers to craft a malicious request, which could be triggered by a victim unknowingly. In a successful CSRF attack, the attacker could lead the victim user to carry out an action unintentionally.

Affected products

  • Westermo l206-f2g Firmware: version 4.24 only

Published 2024-02-06. Last modified 2026-06-17.