Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g66h-9qrm-pfwx

Опубликовано: 01 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of transport layer security allows a man-in-the-middle attacker to intercept and modify traffic between the client and the device.

Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of transport layer security allows a man-in-the-middle attacker to intercept and modify traffic between the client and the device.

EPSS

Процентиль: 2%
0.00014
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 6.8
nvd
2 месяца назад

Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of transport layer security allows a man-in-the-middle attacker to intercept and modify traffic between the client and the device.

EPSS

Процентиль: 2%
0.00014
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-319