Impact
An insecure direct object reference flaw in the firmware of Telesquare SDT‑CS3B1 LTE routers allows attackers to manipulate request parameters and gain unauthorized access to protected resources, exposing sensitive configuration and operational functions. The weakness, identified as CWE‑639, permits retrieval or modification of data that should be protected, threatening the confidentiality and integrity of the device.
Affected Systems
Devices that operate on the Telesquare SDT‑CS3B1 LTE router with firmware versions 1.1.0 or 1.2.0 are affected. Any router running these firmware releases remains vulnerable unless the firmware is updated to a patched version or mitigations are otherwise applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.3, signifying critical severity, but its EPSS score is below 1 % and it is not listed in CISA’s KEV catalog, suggesting a low likelihood of widespread exploitation. Based on the description, the attack likely proceeds by sending crafted HTTP requests that manipulate user‑supplied parameters to reference protected objects and bypass authentication controls.
OpenCVE Enrichment