Kaon AR2140X 路由器在对未认证的 HTTP 请求进行响应时,不当地区分并颁发会话 Cookie。该漏洞允许远程攻击者在未提供凭据的情况下获取有效的会话标识符,从而实现身份验证绕过。利用此访问权限,攻击者可以针对升级相关功能执行未经授权的恶意操作。这些操作可被滥用,强制路由器向任意选定的域名发起 GET 请求。 该问题已在固件版本 4.2.17 及更早版本中被发现,较新版本的状况目前尚不明确。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet