Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w6wm-hqx9-7cq8

Опубликовано: 24 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 9.8

Описание

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exposure, or token reuse on a shared system) can continue to authenticate to the management interface until the token is revoked, enabling unauthorized access to device functions and data.

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exposure, or token reuse on a shared system) can continue to authenticate to the management interface until the token is revoked, enabling unauthorized access to device functions and data.

EPSS

Процентиль: 62%
0.00414
Низкий

8.7 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 9.8
nvd
3 месяца назад

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exposure, or token reuse on a shared system) can continue to authenticate to the management interface until the token is revoked, enabling unauthorized access to device functions and data.

EPSS

Процентиль: 62%
0.00414
Низкий

8.7 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-613