漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Router console accessible without authentication
Vulnerability Description
The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the configuration, the session state is shared. If any other user is currently logged in, the anonymous user can execute commands in the context of the authenticated one. If the logged in user has administrative privileges, it is possible to use webadmin service configuration commands to create a new admin user with a chosen password.
CVSS Information
N/A
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
Hongdian Router H8951-4G-ESP 安全漏洞
Vulnerability Description
Hongdian Router H8951-4G-ESP是中国宏电(Hongdian)公司的一款无线路由器。 Hongdian Router H8951-4G-ESP 2310271149之前版本存在安全漏洞,该漏洞源于无需在“data”字段进行身份验证即可访问路由器控制台。攻击者利用该漏洞可以在用户环境中执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A