GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or access logs, potentially allowing attackers to bypass authentication via session replay.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-06-13T00:00:00
Updated: 2024-08-02T15:47:06.473Z
Reserved: 2023-05-22T00:00:00
Link: CVE-2023-33621
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-06-13T16:15:13.027
Modified: 2024-11-21T08:05:46.173
Link: CVE-2023-33621
Redhat
No data.