CVE-2024-26153: Etictelecom Remote Access Server Firmware

High severity, CVSS 7.4. EPSS: 0.2% chance of exploitation in the next 30 days.

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (CSRF). An external attacker with no access to the device can force the end user into submitting a "setconf" method request, not requiring any CSRF token, which can lead into denial of service on the device.

Affected products

  • Etictelecom Remote Access Server Firmware: before 4.9.19 (fixed in 4.9.19)

Published 2025-01-17. Last modified 2026-06-17.