Cross‑Site Request Forgery in Link Aggregation Configuration
Summary
| CVE | CVE-2026-22323 |
|---|---|
| State | PUBLISHED |
| Assigner | CERTVDE |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-03-18 08:16:30 UTC |
| Updated | 2026-04-27 19:22:08 UTC |
| Description | A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick authenticated users into sending unauthorized POST requests to the device by luring them to a malicious webpage. This can silently alter the device’s configuration without the victim’s knowledge or consent. Availability impact was set to low because after a successful attack the device will automatically recover without external intervention. |
Risk And Classification
Primary CVSS: v3.1 7.1 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
EPSS: 0.000140000 probability, percentile 0.024480000 (date 2026-04-27)
Problem Types: CWE-352 | CWE-352 CWE-352 Cross-Site Request Forgery (CSRF)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L |
| 3.1 | CNA | CVSS | 7.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
NoneIntegrity
HighAvailability
LowCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Phoenix Contact | FL SWITCH 2005 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2008 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2016 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2105 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2108 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2116 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2204-2TC-2SFX | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2205 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2206-2FX | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2206-2FX SM | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2206-2FX SM ST | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2206-2FX ST | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2206-2SFX | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2206-2SFX PN | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2206C-2FX | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2207-FX | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2207-FX SM | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2208 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2208 PN | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2208C | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2212-2TC-2SFX | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2214-2FX | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2214-2FX SM | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2214-2SFX | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2214-2SFX PN | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2216 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2216 PN | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2304-2GC-2SFP | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2306-2SFP | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2306-2SFP PN | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2308 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2308 PN | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2312-2GC-2SFP | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2314-2SFP | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2314-2SFP PN | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2316 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2316 PN | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2404-2TC-2SFX | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2406-2SFX | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2406-2SFX PN | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2408 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2408 PN | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2412-2TC-2SFX | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2414-2SFX | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2414-2SFX PN | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2416 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2416 PN | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2504-2GC-2SFP | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2506-2SFP | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2506-2SFP PN | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2508 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2508 PN | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2512-2GC-2SFP | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2514-2SFP | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2514-2SFP PN | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2516 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2516 PN | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2608 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2608 PN | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2708 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2708 PN | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2303-8SP1 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL NAT 2008 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL NAT 2208 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL NAT 2304-2GC-2SFP | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2008F | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2316/K1 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2506-2SFP/K1 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 2508/K1 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH TSN 2316 | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH TSN 2312-2GC-2SFP | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH TSN 2314-2SFP | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 5924-4GC | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 5916-8GC-4SFP | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 5924SFP-4GC | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 5924-4SFP | affected 0.0.0 3.53 semver | Not specified |
| CNA | Phoenix Contact | FL SWITCH 5916SFP-8GC-4SFP | affected 0.0.0 3.53 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| certvde.com/de/advisories/VDE-2025-104 | [email protected] | certvde.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Gabriele Quagliarella from Nozomi Networks (en)
There are currently no legacy QID mappings associated with this CVE.