Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c52c-f827-gfpg

Опубликовано: 29 янв. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. All the Get APIs that are not included in cgi_check_ability are already executable by any logged-in users. An attacker can send an HTTP request to trigger this vulnerability.

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. All the Get APIs that are not included in cgi_check_ability are already executable by any logged-in users. An attacker can send an HTTP request to trigger this vulnerability.

EPSS

Процентиль: 51%
0.00284
Низкий

8.8 High

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. All the Get APIs that are not included in cgi_check_ability are already executable by any logged-in users. An attacker can send an HTTP request to trigger this vulnerability.

EPSS

Процентиль: 51%
0.00284
Низкий

8.8 High

CVSS3

Дефекты

CWE-276