Описание
Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:aztech:wmb250ac_firmware:016_2020:*:*:*:*:*:*:*
cpe:2.3:h:aztech:wmb250ac:-:*:*:*:*:*:*:*
EPSS
Процентиль: 93%
0.10399
Средний
8.8 High
CVSS3
Дефекты
CWE-77
CWE-77
Связанные уязвимости
CVSS3: 8.8
github
почти 3 года назад
Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login.
EPSS
Процентиль: 93%
0.10399
Средний
8.8 High
CVSS3
Дефекты
CWE-77
CWE-77