Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-345j-gpg7-fhmx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to use all features provided by the router. Examples: change the router password, retrieve the Wi-Fi passphrase, send an SMS message, or modify the IP forwarding to access the internal network.

The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to use all features provided by the router. Examples: change the router password, retrieve the Wi-Fi passphrase, send an SMS message, or modify the IP forwarding to access the internal network.

EPSS

Процентиль: 65%
0.00501
Низкий

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9.1
nvd
почти 5 лет назад

The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to use all features provided by the router. Examples: change the router password, retrieve the Wi-Fi passphrase, send an SMS message, or modify the IP forwarding to access the internal network.

EPSS

Процентиль: 65%
0.00501
Низкий

Дефекты

CWE-306