Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jww6-hm47-4x25

Опубликовано: 29 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.8

Описание

The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials.

The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials.

EPSS

Процентиль: 5%
0.00022
Низкий

6.8 Medium

CVSS4

Дефекты

CWE-261

Связанные уязвимости

nvd
4 месяца назад

The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials.

EPSS

Процентиль: 5%
0.00022
Низкий

6.8 Medium

CVSS4

Дефекты

CWE-261