Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-25rm-p4h5-753p

Опубликовано: 13 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any HTTP request to an unauthenticated page to force the server to generate a SESSION_ID, and using this SESSION_ID an attacker can then perform authenticated requests.

Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any HTTP request to an unauthenticated page to force the server to generate a SESSION_ID, and using this SESSION_ID an attacker can then perform authenticated requests.

EPSS

Процентиль: 27%
0.00096
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 5.4
nvd
больше 2 лет назад

Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any HTTP request to an unauthenticated page to force the server to generate a SESSION_ID, and using this SESSION_ID an attacker can then perform authenticated requests.

EPSS

Процентиль: 27%
0.00096
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-287