Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6pwv-hr7p-g77v

Опубликовано: 11 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access content. In order to serve static content, the application performs a check for the existence of specific characters in the URL (.css, .png etc). If it exists, it performs a "fake login" to give the request an active session to load the file and not redirect to the login page.

Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access content. In order to serve static content, the application performs a check for the existence of specific characters in the URL (.css, .png etc). If it exists, it performs a "fake login" to give the request an active session to load the file and not redirect to the login page.

EPSS

Процентиль: 45%
0.00226
Низкий

7.5 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.5
nvd
около 3 лет назад

Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access content. In order to serve static content, the application performs a check for the existence of specific characters in the URL (.css, .png etc). If it exists, it performs a "fake login" to give the request an active session to load the file and not redirect to the login page.

CVSS3: 9.8
fstec
около 3 лет назад

Уязвимость функции strstr() микропрограммного обеспечения маршрутизаторов Netcomm NF20, NF20MESH, NL1902, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 45%
0.00226
Низкий

7.5 High

CVSS3

Дефекты

CWE-287