In Bitaxe ESP-Miner before 2.5.0 with AxeOS, one can use an /api/system CSRF attack to update the payout address (aka stratumUser) for a Bitaxe Bitcoin miner, or change the frequency and voltage settings.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-03-03 00:15
Updated : 2025-03-04 19:15
NVD link : CVE-2025-27579
Mitre link : CVE-2025-27579
CVE.ORG link : CVE-2025-27579
JSON object : View
Products Affected
No product.
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
