PT-2024-13712 · Hongdian · H8951-4G-Esp+1

Robert Pogorzelski

·

Published

2024-01-12

·

Updated

2024-01-19

·

CVE-2023-49255

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The router console is accessible without authentication at the data field. Although a user needs to be logged in to modify the configuration, the session state is shared. If another user is currently logged in, an anonymous user can execute commands in the context of the authenticated one. If the logged-in user has administrative privileges, it is possible to use webadmin service configuration commands to create a new admin user with a chosen password.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-49255

Affected Products

H8951-4G-Esp
H8951-4G-Esp Firmware