Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8gqp-3rhh-936h

Опубликовано: 13 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10
CVSS3: 10

Описание

Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has learned the identity of a legitimate user.

Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has learned the identity of a legitimate user.

EPSS

Процентиль: 42%
0.00201
Низкий

10 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 10
nvd
26 дней назад

Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has learned the identity of a legitimate user.

EPSS

Процентиль: 42%
0.00201
Низкий

10 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-639