JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to cross-site request forgery (CSRF) attacks, allowing attackers to perform administrative actions on behalf of authenticated users without their knowledge or consent.
History

Tue, 13 Jan 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Jm-data
Jm-data onu Jf511-tv
Jm-data onu Jf511-tv Firmware
CPEs cpe:2.3:h:jm-data:onu_jf511-tv:-:*:*:*:*:*:*:*
cpe:2.3:o:jm-data:onu_jf511-tv_firmware:1.0.55:*:*:*:*:*:*:*
cpe:2.3:o:jm-data:onu_jf511-tv_firmware:1.0.62:*:*:*:*:*:*:*
cpe:2.3:o:jm-data:onu_jf511-tv_firmware:1.0.67:*:*:*:*:*:*:*
Vendors & Products Jm-data
Jm-data onu Jf511-tv
Jm-data onu Jf511-tv Firmware

Fri, 02 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Dec 2025 23:00:00 +0000

Type Values Removed Values Added
Description JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to cross-site request forgery (CSRF) attacks, allowing attackers to perform administrative actions on behalf of authenticated users without their knowledge or consent.
Title JM-DATA ONU JF511-TV 1.0.67 Cross-Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-30T22:41:42.422Z

Updated: 2026-01-02T14:39:35.502Z

Reserved: 2025-12-27T13:53:29.755Z

Link: CVE-2022-50804

cve-icon Vulnrichment

Updated: 2026-01-02T14:25:54.682Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-30T23:15:47.987

Modified: 2026-01-13T21:34:21.860

Link: CVE-2022-50804

cve-icon Redhat

No data.