Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
EFM ipTIME A3004T Session Validation httpcon_check_session_url improper authentication
Vulnerability Description
A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper authentication. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
认证机制不恰当
Vulnerability Title
EFM ipTIME A3004T 授权问题漏洞
Vulnerability Description
EFM ipTIME A3004T是韩国EFM公司的一款无线路由器。 EFM ipTIME A3004T 14.19.0版本存在授权问题漏洞,该漏洞源于Session Validation组件中httpcon_check_session_url函数存在身份验证不当问题,可能导致远程攻击者利用该漏洞。
CVSS Information
N/A
Vulnerability Type
N/A