CVE Published: 03/11/2023 |
CVE Updated: 04/09/2024 |
CVE Year: 2023 Source: twcert |
Vendor: Chunghwa Telecom |
Product: NOKIA G-040W-Q Status : PUBLISHED
CVE-2023-41351 Description
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an administrator, to perform arbitrary system operations or disrupt service.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H