Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Bitaxe ESP-Miner before 2.5.0 with AxeOS, one can use an /api/system CSRF attack to update the payout address (aka stratumUser) for a Bitaxe Bitcoin miner, or change the frequency and voltage settings.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
ESP-Miner 跨站请求伪造漏洞
Vulnerability Description
ESP-Miner是Skot个人开发者的一个 ESP32 的比特币相关程序。 ESP-Miner 2.5.0之前版本存在安全漏洞。攻击者利用该漏洞可以修改支付地址或频率和电压的设置。
CVSS Information
N/A
Vulnerability Type
N/A