Metrics
Affected Vendors & Products
Fri, 16 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 14 Jan 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:kyocera:net_admin:3.4.0906:*:*:*:*:*:*:* |
Mon, 29 Dec 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kyocera
Kyocera net Admin |
|
| Vendors & Products |
Kyocera
Kyocera net Admin |
Wed, 24 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | KYOCERA Net Admin 3.4.0906 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can craft malicious web pages that automatically submit forms to add new admin accounts with predefined credentials when a logged-in user visits the page. | |
| Title | KYOCERA Net Admin 3.4.0906 Cross-Site Request Forgery via User Administration | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-24T19:28:04.889Z
Updated: 2026-01-16T18:59:58.350Z
Reserved: 2025-12-24T14:27:12.478Z
Link: CVE-2019-25254
Updated: 2025-12-24T20:01:22.076Z
Status : Modified
Published: 2025-12-24T20:15:54.010
Modified: 2026-01-16T19:16:04.333
Link: CVE-2019-25254
No data.
ReportizFlow