Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c83q-fq82-79pj

Опубликовано: 19 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home.html endpoint. An attacker can access an active session without authentication, allowing them to control the device, modify configurations, and compromise system integrity.

The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home.html endpoint. An attacker can access an active session without authentication, allowing them to control the device, modify configurations, and compromise system integrity.

EPSS

Процентиль: 36%
0.0015
Низкий

7.5 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.5
nvd
3 месяца назад

The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home.html endpoint. An attacker can access an active session without authentication, allowing them to control the device, modify configurations, and compromise system integrity.

EPSS

Процентиль: 36%
0.0015
Низкий

7.5 High

CVSS3

Дефекты

CWE-284