Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hmwm-86jc-9m8g

Опубликовано: 27 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The devices are vulnerable to an authentication bypass due to flaws in the authorization mechanism. An unauthenticated remote attacker could exploit this weakness by performing brute-force attacks to guess valid credentials or by using MD5 collision techniques to forge authentication hashes, potentially compromising the device.

The devices are vulnerable to an authentication bypass due to flaws in the authorization mechanism. An unauthenticated remote attacker could exploit this weakness by performing brute-force attacks to guess valid credentials or by using MD5 collision techniques to forge authentication hashes, potentially compromising the device.

EPSS

Процентиль: 24%
0.00081
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-328
CWE-656

Связанные уязвимости

CVSS3: 9.8
nvd
9 месяцев назад

The devices are vulnerable to an authentication bypass due to flaws in the authorization mechanism. An unauthenticated remote attacker could exploit this weakness by performing brute-force attacks to guess valid credentials or by using MD5 collision techniques to forge authentication hashes, potentially compromising the device.

EPSS

Процентиль: 24%
0.00081
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-328
CWE-656