Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4cc6-4h77-4425

Опубликовано: 08 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.4

Описание

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /cgi-bin/system-tool accept unauthenticated requests with empty or invalid session values. This design flaw lets attackers piggyback on another user's active session to retrieve sensitive configuration data or execute privileged actions without authentication.

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /cgi-bin/system-tool accept unauthenticated requests with empty or invalid session values. This design flaw lets attackers piggyback on another user's active session to retrieve sensitive configuration data or execute privileged actions without authentication.

EPSS

Процентиль: 50%
0.00268
Низкий

9.4 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.4
nvd
около 1 месяца назад

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /cgi-bin/system-tool accept unauthenticated requests with empty or invalid session values. This design flaw lets attackers piggyback on another user's active session to retrieve sensitive configuration data or execute privileged actions without authentication.

EPSS

Процентиль: 50%
0.00268
Низкий

9.4 Critical

CVSS3

Дефекты

CWE-287