Telesquare SKT LTE Router SDT-CS3B1 Insecure Direct Object Reference
Vulnerability Description
Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access resources by manipulating user-supplied input parameters. Attackers can directly reference objects in the system to retrieve sensitive information and access functionalities without proper access controls.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-20223
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- LiquidWorm as Gjoko Krstic of Zero Science Lab
References
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2017-5445.php
- https://www.exploit-db.com/exploits/43402/
- https://packetstormsecurity.com/files/145551
- https://cxsecurity.com/issue/WLB-2017120297
- https://exchange.xforce.ibmcloud.com/vulnerabilities/136993
- https://www.vulncheck.com/advisories/telesquare-skt-lte-router-sdt-cs3b1-insecure-direct-object-reference
More from Telesquare
View All →Affected Vendor
Telesquare
View all reports →