Impact
The vulnerability in the IpRestrictAccess middleware of simple‑php‑router allows an attacker to forge HTTP headers such as X‑Forwarded‑For, CF‑Connecting‑IP, or Client‑IP. By spoofing these values, an unauthenticated remote user can impersonate a whitelisted address or bypass a blacklist and gain access to routes that are intended to be IP‑restricted. The flaw falls under CWE‑348, which describes IP address spoofing attacks. As a result, application logic that relies on IP checks can be subverted, potentially exposing sensitive functionality or data.
Affected Systems
The build of simple‑php‑router through version 5.4.1.7 is affected. This affects deployments that mount Pecee’s simple‑router package without updating beyond the listed version. No other vendor or product has been identified as impacted within this CVE entry.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high risk level. Because the EPSS score is unavailable, the exact likelihood of exploitation remains unclear, but the absence of a KEV listing suggests no confirmed widespread exploitation yet. The likely attack vector is remote HTTP requests to an application that uses the IpRestrictAccess middleware; it requires that the server does not restrict or sanitize forwarded‑for style headers. In practice, any client that can send arbitrary HTTP requests to the router can attempt to spoof headers and test whether the middleware is enforcing real source IPs. The vulnerability’s impact is limited to the authentication or restriction model in place, but compromising a protected route could allow further exploitation such as privilege escalation or data disclosure.
OpenCVE Enrichment