Router console accessible without authentication
Vulnerability Description
The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the configuration, the session state is shared. If any other user is currently logged in, the anonymous user can execute commands in the context of the authenticated one. If the logged in user has administrative privileges, it is possible to use webadmin service configuration commands to create a new admin user with a chosen password.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-49255
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Robert Pogorzelski (SEQRED)
References
More from Hongdian
View All →Affected Vendor
Hongdian
View all reports →