Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wwpc-74vx-c2x3

Опубликовано: 20 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6

Описание

This vulnerability exists in the CP Plus Router due to insecure handling of cookie flags used within its web interface. A remote attacker could exploit this vulnerability by intercepting data transmissions during an HTTP session on the vulnerable system.

Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and compromise the targeted system.

This vulnerability exists in the CP Plus Router due to insecure handling of cookie flags used within its web interface. A remote attacker could exploit this vulnerability by intercepting data transmissions during an HTTP session on the vulnerable system.

Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and compromise the targeted system.

EPSS

Процентиль: 35%
0.00143
Низкий

8.6 High

CVSS4

Дефекты

CWE-614

Связанные уязвимости

nvd
около 1 года назад

This vulnerability exists in the CP Plus Router due to insecure handling of cookie flags used within its web interface. A remote attacker could exploit this vulnerability by intercepting data transmissions during an HTTP session on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and compromise the targeted system.

EPSS

Процентиль: 35%
0.00143
Низкий

8.6 High

CVSS4

Дефекты

CWE-614