Impact
A server‑side request forgery vulnerability exists in the built‑in HTTP API service of mifi lossless‑cut. The flaw allows an attacker to instruct the service to make arbitrary HTTP requests to internal or external hosts, potentially exposing sensitive data or enabling further attacks. The vulnerability is enabled by a feature behind an experimental command‑line flag and could involve NTLM authentication to internal resources.
Affected Systems
The issue affects mifi lossless‑cut versions up to 3.69.0. Any installation that uses the built‑in HTTP API service with the experimental flag enabled is susceptible.
Risk and Exploitability
The CVSS base score is 2.3, reflecting a low overall impact. Exploitation requires access to the local network, has high complexity, and is known to be difficult. No EPSS information is available, and the CVE is not listed in the CISA KEV catalog. However, the vulnerability has been publicly disclosed, so the risk is moderate in environments where the API service is reachable from untrusted hosts.
OpenCVE Enrichment