PT-2024-13712 · Hongdian · H8951-4G-Esp+1
Robert Pogorzelski
·
Published
2024-01-12
·
Updated
2024-01-19
·
CVE-2023-49255
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
No specific software or versions are mentioned in the provided descriptions.
Description
The router console is accessible without authentication at the
data field. Although a user needs to be logged in to modify the configuration, the session state is shared. If another user is currently logged in, an anonymous user can execute commands in the context of the authenticated one. If the logged-in user has administrative privileges, it is possible to use webadmin service configuration commands to create a new admin user with a chosen password.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
H8951-4G-Esp
H8951-4G-Esp Firmware