PT-2026-4648 · Lcg0124 · Bootdo

Tom132432

·

Published

2026-01-25

·

Updated

2026-01-25

·

CVE-2026-1406

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions lcg0124 BootDo versions prior to 5ccd963c74058036b466e038cff37de4056c1600
Description An open redirect issue exists in lcg0124 BootDo. The vulnerability is related to the manipulation of the Hostname argument within the redirectToLogin function of the AccessControlFilter.java file, part of the Host Header Handler component. This manipulation can lead to an open redirect, and the attack can be initiated remotely. The exploit has been publicly disclosed.
Recommendations Versions prior to 5ccd963c74058036b466e038cff37de4056c1600 should be updated. As a temporary workaround, consider restricting or disabling the redirectToLogin function until an update is available.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2026-1406

Affected Products

Bootdo