CVE-2026-1835 PUBLISHED

lcg0124 BootDo cross-site request forgery

Assigner: VulDB
Reserved: 03.02.2026 Published: 04.02.2026 Updated: 04.02.2026

A vulnerability was identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. This affects an unknown part. The manipulation leads to cross-site request forgery. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor lcg0124
Product BootDo
Versions
  • Version e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb is affected

Credits

  • Tom132432 (VulDB User) reporter

References

Problem Types

  • Cross-Site Request Forgery CWE
  • Missing Authorization CWE