Back to Database
Status published
Unknown
CVE-2023-49261
Sensitive authentication-related value accessible publicly
Vulnerability Description
The "tokenKey" value used in user authorization is visible in the HTML source of the login page.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-49261
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Robert Pogorzelski (SEQRED)
References
More from Hongdian
View All →CVE-2023-49262
Buffer overflow vulnerability in Cookie authentication field
Unknown
0
CVE-2023-49260
Stored cross-site scripting vulnerability
Unknown
0
CVE-2023-49259
Bruteforcing authentication cookie for a given user
Unknown
0
CVE-2023-49258
Reflected cross-site scripting vulnerability
Unknown
0
CVE-2023-49257
Command execution using the certificate upload utility
Unknown
0
Affected Vendor
Hongdian
View all reports →Affected Software
H8951-4G-ESP
Vulnerable Versions:
0
Timeline
Official Publish:
January 12th, 2024
Last Modified:
October 10th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available