CVE-2025-14266: Ercom Cryptobox

Low severity, CVSS 0.6. EPSS: 0.2% chance of exploitation in the next 30 days.

CSRF in Ercom Cryptobox administration console allows attacker to trigger some actions on behalf of a Cryptobox administrator. The attack requires the administrator to browse a malicious web site or to click a link while he has an open session on the administration console.

Affected products

  • Ercom Cryptobox: from 4.0.0, before 4.37.229 (fixed in 4.37.229); from 4.38.0, before 4.39.200 (fixed in 4.39.200)

Published 2025-12-17. Last modified 2026-06-17.