Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very easy for bots to bypass the captcha check and more susceptible to brute force attacks.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-45853 Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very easy for bots to bypass the captcha check and more susceptible to brute force attacks.
Fixes

Solution

Update version to G040WQR231013.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-09-06T19:56:30.968Z

Reserved: 2023-08-29T00:11:47.812Z

Link: CVE-2023-41350

cve-icon Vulnrichment

Updated: 2024-08-02T19:01:34.240Z

cve-icon NVD

Status : Modified

Published: 2023-11-03T05:15:29.930

Modified: 2024-11-21T08:21:07.740

Link: CVE-2023-41350

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.