### [CVE-2018-7828](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7828) ![](https://img.shields.io/static/v1?label=Product&message=Pelco%20Sarix%20Enhanced%20and%20Spectra%20Enhanced%2C%20Pelco%20Sarix%20Enhanced%201st%20generation%20and%20Spectra%20Enhanced%20PTZ&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Multiple%20Vulnerabilities&color=brighgreen) ### Description A Cross-Site Request Forgery (CSRF) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera when an authenticated user clicks a specially crafted malicious link while logged into the camera. ### POC #### Reference - https://www.schneider-electric.com/en/download/document/SEVD-2019-045-03/ - https://www.schneider-electric.com/en/download/document/SEVD-2019-045-03/ #### Github No PoCs found on GitHub currently.