Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w6x6-2wp3-jqvp

Опубликовано: 03 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an administrator, to perform arbitrary system operations or disrupt service.

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an administrator, to perform arbitrary system operations or disrupt service.

EPSS

Процентиль: 25%
0.00086
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-288
CWE-306

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an administrator, to perform arbitrary system operations or disrupt service.

EPSS

Процентиль: 25%
0.00086
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-288
CWE-306