Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sn0Ox

#18915of 53,624
14.2Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2023-14736
5.4
2023-02-13
Comfast · Comfast Cf-Wr6110N · CVE-2022-45724
**Name of the Vulnerable Software and Affected Versions** Comfast router CF-WR6110N version 2.3.1 **Description** The issue allows a remote attacker on the same network to perform any HTTP request to an unauthenticated page, forcing the server to generate a `SESSION ID`. Using this `SESSION ID`, an attacker can then perform authenticated requests. **Recommendations** For Comfast router CF-WR6110N version 2.3.1, consider restricting access to unauthenticated pages to prevent the generation of a `SESSION ID` until a patch is available. As a temporary workaround, disabling the use of `SESSION ID` for authentication may help minimize the risk of exploitation.
PT-2023-14737
8.8
2023-02-13
Comfast · Comfast Cf-Wr6110N · CVE-2022-45725
**Name of the Vulnerable Software and Affected Versions** Comfast router CF-WR6110N version 2.3.1 **Description** The issue is related to improper input validation, allowing a remote attacker on the same network to execute arbitrary code on the target via an HTTP POST request. **Recommendations** For Comfast router CF-WR6110N version 2.3.1, update to a newer version that addresses the improper input validation issue to prevent remote code execution.