4.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U
Description
A vulnerability affecting the detailed versions of Cryptobox allows a legitimate user to prevent another to login by triggering an account lockout via sending a specially crafted request.
Basic Information
ID
CVE-2026-5794
Source
THA-PSIRT
Published
Apr 28, 2026 at 17:09
Affected Product
Vendor
Ercom
Product
Cryptobox
Version
4.40.175
Affected Versions
Ercom Cryptobox 4.40.175
Ercom Cryptobox 4.37.237
Ercom Cryptobox 4.37.237