Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The web management portal on the SMC SMCD3G-CCR (aka Comcast Business Gateway) with firmware before 1.4.0.49.2 uses predictable session IDs based on time values, which makes it easier for remote attackers to hijack sessions via a brute-force attack on the userid cookie.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Smc_Networks SMC SMCD3G-CCR web管理门户会话劫持漏洞
Vulnerability Description
带有1.4.0.49.2之前版本固件的SMC SMCD3G-CCR(又名Comcast Business Gateway)的web管理门户使用了基于时间值的可预测会话ID。远程攻击者更容易借助基于用户名cookie的暴力攻击劫持会话。
CVSS Information
N/A
Vulnerability Type
N/A