LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-22323

Published
CVSS7.1
Severityhigh
WeaknessCWE-352
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L

Description

A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick authenticated users into sending unauthorized POST requests to the device by luring them to a malicious webpage. This can silently alter the device’s configuration without the victim’s knowledge or consent. Availability impact was set to low because after a successful attack the device will automatically recover without external intervention.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-22323

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-22323.