Description
Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authentication Abuse.

This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.
Published: 2026-07-02
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing authentication in a critical function of TR7 Cyber Defense Inc.'s WAF‑ASP creates a vulnerability that allows unauthenticated users to invoke privileged operations or view sensitive configuration data. This flaw is classified as CWE‑306, an improper login or authentication control, and is inferred from the description that authentication checks are absent. The lack of authentication checks suggests that any system using the exposed interface can be compromised if accessed by an attacker.

Affected Systems

TR7 Cyber Defense Inc.’s WAF‑ASP versions from 1.0.324.900 up through 1.4.0.116 are affected. Any appliance running one of these releases is vulnerable and requires an update to a fixed version.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity while the EPSS score below 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is reaching the WAF‑ASP management interface over the network, either internal or remote, which is inferred from the description that unauthenticated access is possible. Once network reachability is achieved, the attacker can trigger the unauthenticated endpoint, gaining unauthorized execution of privileged functions and potential access to protected resources. The exploitation path is straightforward in the presence of network reachability due to the absence of proper authentication control.

Generated by OpenCVE AI on July 21, 2026 at 11:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to WAF‑ASP v1.4.0.117 or later.
  • Restrict the WAF‑ASP management interface to trusted IP ranges or enforce VPN access.
  • Enable and monitor authentication logs to detect unauthenticated usage attempts.

Generated by OpenCVE AI on July 21, 2026 at 11:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Description Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.
Title Improper Access Control in TR7's WAF-ASP
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-02T13:48:08.975Z

Reserved: 2026-03-24T12:59:26.386Z

Link: CVE-2026-4767

cve-icon Vulnrichment

Updated: 2026-07-02T13:48:05.328Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:30:06Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function