Xovis PC-series sensors firmware through 3.6.0 allow Cross-Site Request Forgery (CSRF).
The PC-series sensor firmware authenticates users in a way which makes CSRF requests possible.
All PC-series sensor firmware versions up to and including 3.6.0.
Apply the PC-series sensor firmware 3.7.0 or newer and disable legacy authentication.
If the default password(s) are changed, an attacker must first gain knowledge of a valid password.
Xovis would like to thank Ayushman Dutta for responsibly reporting this vulnerability to protect our customers.