Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5gr3-r9jq-3qcj

Опубликовано: 14 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and does not not use session tokens. Therefore, if an attacker changes their IP address to match the logged-in administrator's, or is behind the same NAT as the logged in administrator, session takeover is possible.

The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and does not not use session tokens. Therefore, if an attacker changes their IP address to match the logged-in administrator's, or is behind the same NAT as the logged in administrator, session takeover is possible.

EPSS

Процентиль: 29%
0.00103
Низкий

8.8 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and does not not use session tokens. Therefore, if an attacker changes their IP address to match the logged-in administrator's, or is behind the same NAT as the logged in administrator, session takeover is possible.

CVSS3: 8.8
fstec
больше 3 лет назад

Уязвимость микропрограммного обеспечения Wi-Fi-маршрутизатора WAVLINK Quantum D4G (WN531G3), связанная с недостатками процедуры аутентификации, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 29%
0.00103
Низкий

8.8 High

CVSS3

Дефекты

CWE-287