SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-49255

If any other user is currently logged in, the anonymous user can execute commands in the context of the authenticated one.

CRITICAL 9.8EPSS 0.72%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.72%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the configuration, the session state is shared. If any other user is currently logged in, the anonymous user can execute commands in the context of the authenticated one. If the logged in user has administrative privileges, it is possible to use webadmin service configuration commands to create a new admin user with a chosen password.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.72% probability · 52th percentile
CISA KEV
Not listed
Weakness
CWE-306
Affected
hongdian/h8951-4g-esp firmware
Source
cvd@cert.pl

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.