Description
Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access resources by manipulating user-supplied input parameters. Attackers can directly reference objects in the system to retrieve sensitive information and access functionalities without proper access controls.
Published: 2026-03-16
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Immediate Patch
AI Analysis

Impact

An insecure direct object reference flaw in the firmware of Telesquare SDT‑CS3B1 LTE routers allows attackers to manipulate request parameters and gain unauthorized access to protected resources, exposing sensitive configuration and operational functions. The weakness, identified as CWE‑639, permits retrieval or modification of data that should be protected, threatening the confidentiality and integrity of the device.

Affected Systems

Devices that operate on the Telesquare SDT‑CS3B1 LTE router with firmware versions 1.1.0 or 1.2.0 are affected. Any router running these firmware releases remains vulnerable unless the firmware is updated to a patched version or mitigations are otherwise applied.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.3, signifying critical severity, but its EPSS score is below 1 % and it is not listed in CISA’s KEV catalog, suggesting a low likelihood of widespread exploitation. Based on the description, the attack likely proceeds by sending crafted HTTP requests that manipulate user‑supplied parameters to reference protected objects and bypass authentication controls.

Generated by OpenCVE AI on March 22, 2026 at 15:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify the firmware version deployed on each SDT‑CS3B1 router
  • If a vendor patch that fixes the IDOR flaw is available, install it as soon as possible
  • Restrict access to the router’s management interface to trusted hosts only, for example by implementing network segmentation or firewall rules
  • Disable any unused management interfaces or APIs to limit exposure
  • Regularly review router logs for signatures of unauthorized configuration access

Generated by OpenCVE AI on March 22, 2026 at 15:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 16 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 16 Mar 2026 01:45:00 +0000

Type Values Removed Values Added
Description Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access resources by manipulating user-supplied input parameters. Attackers can directly reference objects in the system to retrieve sensitive information and access functionalities without proper access controls.
Title Telesquare SKT LTE Router SDT-CS3B1 Insecure Direct Object Reference
First Time appeared Telesquare
Telesquare sdt-cs3b1
Telesquare sdt-cs3b1 Firmware
Weaknesses CWE-639
CPEs cpe:2.3:h:telesquare:sdt-cs3b1:-:*:*:*:*:*:*:*
cpe:2.3:o:telesquare:sdt-cs3b1_firmware:1.1.0:*:*:*:*:*:*:*
cpe:2.3:o:telesquare:sdt-cs3b1_firmware:1.2.0:*:*:*:*:*:*:*
Vendors & Products Telesquare
Telesquare sdt-cs3b1
Telesquare sdt-cs3b1 Firmware
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Telesquare Sdt-cs3b1 Sdt-cs3b1 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-04-07T14:03:42.716Z

Reserved: 2026-03-15T21:57:06.190Z

Link: CVE-2017-20223

cve-icon Vulnrichment

Updated: 2026-03-16T14:17:01.309Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-16T14:17:52.347

Modified: 2026-04-14T16:57:27.823

Link: CVE-2017-20223

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-23T14:00:45Z

Weaknesses