漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
NetComm NF20MESH < R6B032 Hardcoded AES Key Authentication Bypass
Vulnerability Description
NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by exploiting a hardcoded AES-256 key used to encrypt session cookies for the web management interface. Attackers can forge a valid encrypted session cookie using the shared hardcoded key and bypass authentication checks to obtain full administrative control of the management interface while any legitimate administrator session is active.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
使用硬编码的密码学密钥
Vulnerability Title
NetComm Wireless NF20MESH 加密问题漏洞
Vulnerability Description
NetComm Wireless NF20MESH是澳大利亚NetComm Wireless公司的一款无线路由器。 NetComm Wireless NF20MESH R6B031之前版本存在加密问题漏洞,该漏洞源于存在硬编码AES-256密钥,用于加密Web管理界面的会话Cookie,可能导致未经身份验证的攻击者伪造加密会话Cookie绕过身份验证,获得管理界面的完全管理控制权。
CVSS Information
N/A
Vulnerability Type
N/A