Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fx5x-8xvw-2cw6

Опубликовано: 08 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

Endpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible without authentication. This poses a significant security threat allowing for e.g: administrator account hijacking or AP password changing. The vendor was contacted early about this disclosure but did not respond in any way.

Endpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible without authentication. This poses a significant security threat allowing for e.g: administrator account hijacking or AP password changing. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 10%
0.00035
Низкий

8.7 High

CVSS4

Дефекты

CWE-306

Связанные уязвимости

nvd
9 месяцев назад

Endpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible without authentication. This poses a significant security threat allowing for e.g: administrator account hijacking or AP password changing. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 10%
0.00035
Низкий

8.7 High

CVSS4

Дефекты

CWE-306