Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j9x6-jxc8-5wfq

Опубликовано: 22 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intended to be accessible only after the admin explicitly grants access to a manager-level account. However, a manager-level user can bypass these controls by intercepting and modifying requests.

The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intended to be accessible only after the admin explicitly grants access to a manager-level account. However, a manager-level user can bypass these controls by intercepting and modifying requests.

EPSS

Процентиль: 21%
0.00067
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.8
nvd
5 месяцев назад

The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intended to be accessible only after the admin explicitly grants access to a manager-level account. However, a manager-level user can bypass these controls by intercepting and modifying requests.

EPSS

Процентиль: 21%
0.00067
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-284