Описание
An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /goform/wirelessBasic) that do not enforce authentication. A remote unauthenticated attacker can modify WAN, LAN, and wireless settings directly, leading to privilege escalation and denial of service.
EPSS
Процентиль: 36%
0.00147
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-306
Связанные уязвимости
CVSS3: 9.1
github
около 1 месяца назад
An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /goform/wirelessBasic) that do not enforce authentication. A remote unauthenticated attacker can modify WAN, LAN, and wireless settings directly, leading to privilege escalation and denial of service.
EPSS
Процентиль: 36%
0.00147
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-306