SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-67013

The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin/Referer validation) on critical configuration…

MEDIUM 6.5EPSS 0.17%

Does this matter?

Lower severity and a low EPSS score (0.17%). Track it; it rarely justifies an emergency change on its own.

Description

The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin/Referer validation) on critical configuration endpoints.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
0.17% probability · 7th percentile
CISA KEV
Not listed
Weakness
CWE-352
Affected
etlsystems/d0116s1ula-22454 firmware · etlsystems/d0116s1uia-22474 firmware · etlsystems/c0401s1ula-22418 firmware · etlsystems/c0801s1ula-22420 firmware · etlsystems/c1601s1ula-22422 firmware · etlsystems/c0401s1ula-22455 firmware · etlsystems/c0801s1ula-22457 firmware · etlsystems/c1601s1ula-22459 firmware · etlsystems/c1601s1uia-22479 firmware · etlsystems/d0104d1ula-22411 firmware · etlsystems/d0108d1ula-22413 firmware · etlsystems/d0104d1ula-22451 firmware · etlsystems/d0108d1ula-22453 firmware · etlsystems/d0108d1uia-22473 firmware · etlsystems/c0401d1ula-22419 firmware · etlsystems/c0801d1ula-22421 firmware · etlsystems/c0401d1ula-22456 firmware · etlsystems/c0801d1ula-22458 firmware · etlsystems/c0401d1uia-22476 firmware · etlsystems/h0108d1ula-22431 firmware · +7 more
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.