CVE-2025-56311

In Shenzhen C-Data Technology Co. FD602GW-DX-R410 (firmware v2.2.14), the web management interface contains an authenticated CSRF vulnerability on the reboot endpoint (/boaform/admin/formReboot). An attacker can craft a malicious webpage that, when visited by an authenticated administrator, causes the router to reboot without explicit user consent. This lack of CSRF protection on a sensitive administrative function can lead to denial of service by disrupting network availability.
Configurations

No configuration.

History

28 Oct 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-352

23 Sep 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-23 21:15

Updated : 2025-10-28 21:15


NVD link : CVE-2025-56311

Mitre link : CVE-2025-56311

CVE.ORG link : CVE-2025-56311


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)