Description
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an administrator, to perform arbitrary system operations or disrupt service.
Published: 2023-11-03
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update version to G040WQR231013.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-45854 Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an administrator, to perform arbitrary system operations or disrupt service.
History

No history.

Subscriptions

Nokia G-040w-q G-040w-q Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-09-04T20:10:05.622Z

Reserved: 2023-08-29T00:11:47.812Z

Link: CVE-2023-41351

cve-icon Vulnrichment

Updated: 2024-08-02T19:01:34.243Z

cve-icon NVD

Status : Modified

Published: 2023-11-03T06:15:07.107

Modified: 2024-11-21T08:21:07.877

Link: CVE-2023-41351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses