PT-2026-45446 · Decolua+1 · 9Router
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
decolua 9router versions prior to 0.4.1
Description
Improper authorization occurs in the HTTP Header Handler component due to the manipulation of the
Host argument within the isAuthenticated() function located in the src/dashboardGuard.js file. This issue allows for remote exploitation.Recommendations
Update to version 0.4.1.
Exploit
Fix
Improper Authorization
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
9Router