Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-35758

Опубликовано: 03 мая 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a Authentication Bypass in the Web Interface. This interface does not properly restrict access to internal functionality. Despite presenting a password login page on first access, authentication is not required to access privileged functionality. As such, it's possible to directly access APIs that should not be exposed to an unauthenticated user.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:librewireless:ls9_firmware:7040:*:*:*:*:*:*:*
cpe:2.3:h:librewireless:ls9:-:*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.02035
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a Authentication Bypass in the Web Interface. This interface does not properly restrict access to internal functionality. Despite presenting a password login page on first access, authentication is not required to access privileged functionality. As such, it's possible to directly access APIs that should not be exposed to an unauthenticated user.

EPSS

Процентиль: 83%
0.02035
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-306