PT-2026-4648 · Lcg0124 · Bootdo
Tom132432
·
Published
2026-01-25
·
Updated
2026-01-25
·
CVE-2026-1406
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
lcg0124 BootDo versions prior to 5ccd963c74058036b466e038cff37de4056c1600
Description
An open redirect issue exists in lcg0124 BootDo. The vulnerability is related to the manipulation of the
Hostname argument within the redirectToLogin function of the AccessControlFilter.java file, part of the Host Header Handler component. This manipulation can lead to an open redirect, and the attack can be initiated remotely. The exploit has been publicly disclosed.Recommendations
Versions prior to 5ccd963c74058036b466e038cff37de4056c1600 should be updated. As a temporary workaround, consider restricting or disabling the
redirectToLogin function until an update is available.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bootdo