Логотип exploitDog
bind:CVE-2023-33621
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-33621

Количество 2

Количество 2

nvd логотип

CVE-2023-33621

больше 2 лет назад

GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or access logs, potentially allowing attackers to bypass authentication via session replay.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-cg99-p6r9-c75p

больше 2 лет назад

GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or access logs, potentially allowing attackers to bypass authentication via session replay.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-33621

GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or access logs, potentially allowing attackers to bypass authentication via session replay.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-cg99-p6r9-c75p

GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or access logs, potentially allowing attackers to bypass authentication via session replay.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу