Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-23f5-mvxj-rqhr

Опубликовано: 11 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote unauthenticated attackers to access administrative information-retrieval functions intended for authenticated users. By invoking "get_*" operations, attackers can obtain device configuration data, including plaintext credentials, without authentication or an existing session.

A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote unauthenticated attackers to access administrative information-retrieval functions intended for authenticated users. By invoking "get_*" operations, attackers can obtain device configuration data, including plaintext credentials, without authentication or an existing session.

EPSS

Процентиль: 9%
0.00032
Низкий

7.5 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 6.5
nvd
около 1 месяца назад

A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote unauthenticated attackers to access administrative information-retrieval functions intended for authenticated users. By invoking "get_*" operations, attackers can obtain device configuration data, including plaintext credentials, without authentication or an existing session.

EPSS

Процентиль: 9%
0.00032
Низкий

7.5 High

CVSS3

Дефекты

CWE-287