Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wjqw-p7j2-5gx2

Опубликовано: 23 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.3

Описание

The Intellian C700 web panel allows you to add firewall rules. Each of these rules has an associated ID, but there is a problem when adding a new rule, the ID used to create the database entry may be different from the JSON ID. If the rule needs to be deleted later, the system will use the JSON ID and therefore fail. This can be exploited by an attacker to create rules that cannot be deleted unless the device is reset to factory defaults.

The Intellian C700 web panel allows you to add firewall rules. Each of these rules has an associated ID, but there is a problem when adding a new rule, the ID used to create the database entry may be different from the JSON ID. If the rule needs to be deleted later, the system will use the JSON ID and therefore fail. This can be exploited by an attacker to create rules that cannot be deleted unless the device is reset to factory defaults.

EPSS

Процентиль: 30%
0.00114
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-20

Связанные уязвимости

nvd
9 месяцев назад

The Intellian C700 web panel allows you to add firewall rules. Each of these rules has an associated ID, but there is a problem when adding a new rule, the ID used to create the database entry may be different from the JSON ID. If the rule needs to be deleted later, the system will use the JSON ID and therefore fail. This can be exploited by an attacker to create rules that cannot be deleted unless the device is reset to factory defaults.

EPSS

Процентиль: 30%
0.00114
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-20