Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very easy for bots to bypass the captcha check and more susceptible to brute force attacks.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-45853 | Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very easy for bots to bypass the captcha check and more susceptible to brute force attacks. |
Fixes
Solution
Update version to G040WQR231013.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7500-0c544-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-06T19:56:30.968Z
Reserved: 2023-08-29T00:11:47.812Z
Link: CVE-2023-41350
Updated: 2024-08-02T19:01:34.240Z
Status : Modified
Published: 2023-11-03T05:15:29.930
Modified: 2024-11-21T08:21:07.740
Link: CVE-2023-41350
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD