Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cg99-p6r9-c75p

Опубликовано: 13 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or access logs, potentially allowing attackers to bypass authentication via session replay.

GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or access logs, potentially allowing attackers to bypass authentication via session replay.

EPSS

Процентиль: 18%
0.00056
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-294

Связанные уязвимости

CVSS3: 5.9
nvd
больше 2 лет назад

GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or access logs, potentially allowing attackers to bypass authentication via session replay.

EPSS

Процентиль: 18%
0.00056
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-294